Alexander Kolbasov commented on SENTRY-2134:

I think that supporting URI grants through Sentry may be a reasonable thing to 
do as long as it is clear hw they interplay with regular grants - what happens 
if there is table grant and URI grant? Or there is URI grant on a directory and 
column-level privilege?

Would someone care to draft a proposal of the suggested behavior of URI grants?

> Apply Hive URI grants recursively to subdirectories
> ---------------------------------------------------
>                 Key: SENTRY-2134
>                 URL: https://issues.apache.org/jira/browse/SENTRY-2134
>             Project: Sentry
>          Issue Type: Improvement
>          Components: Hive Binding
>    Affects Versions: 1.8.0, 2.0.0, 1.7.1
>            Reporter: Ruslan Dautkhanov
>            Priority: Major
>              Labels: hive, uri
> Currently we need to add direct grants for all Hive tables' LOCATIONs. 
> Like, 'hdfs_staging/table1', 'hdfs_staging/table2', etc.. 
> It's not manageable this way. - we can't add grants for each and every table. 
> It would be great if we could just do one grant - 
> 'hdfs_staging/' so it would automatically be applied to  
> 'hdfs_staging/table1', 'hdfs_staging/table2', and other subdirectories.
> There is probably a reason this wasn't implemented earlier? Thanks for 
> considering this improvement.
> Also found another user's request on this - 
> https://community.cloudera.com/t5/Interactive-Short-cycle-SQL/Impala-Sentry-GRANT-ALL-ON-URI-not-cascaded-down-through/td-p/39928

This message was sent by Atlassian JIRA

Reply via email to