[ 
https://issues.apache.org/jira/browse/KAFKA-5638?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16113013#comment-16113013
 ] 

Jason Gustafson commented on KAFKA-5638:
----------------------------------------

Yes, compatibility is what I had in mind. I think my thought at the time was 
that {{Describe(Cluster)}} ought to imply {{Describe(Group:*)}}, but this may 
be the only case where we've used permission on one resource to imply 
permission on another (not sure about that). I guess we see this as incorrect 
usage? It would be nice to have some clear semantic guidelines for ACL usage 
since there does seem to be a few inconsistencies.

I think there's certainly an argument for treating the missing 
{{Describe(Group)}} check as a bug since listing the name of a group is less 
exposure than describing the group which is already possible with 
{{Describe(Group)}} permission. On the other hand, if we wanted to clean up the 
ACL model at the same time and drop the {{Describe(Cluster)}} permission, then 
a KIP would be necessary. Thoughts?

> Inconsistency in consumer group related ACLs
> --------------------------------------------
>
>                 Key: KAFKA-5638
>                 URL: https://issues.apache.org/jira/browse/KAFKA-5638
>             Project: Kafka
>          Issue Type: Bug
>          Components: security
>    Affects Versions: 0.11.0.0
>            Reporter: Vahid Hashemian
>            Assignee: Vahid Hashemian
>            Priority: Minor
>              Labels: needs-kip
>
> Users can see all groups in the cluster (using consumer group’s {{--list}} 
> option) provided that they have {{Describe}} access to the cluster. It would 
> make more sense to modify that experience and limit what is listed in the 
> output to only those groups they have {{Describe}} access to. The reason is, 
> almost everything else is accessible by a user only if the access is 
> specifically granted (through ACL {{--add}}); and this scenario should not be 
> an exception. The potential change would be updating the minimum required 
> permission of {{ListGroup}} from {{Describe (Cluster)}} to {{Describe 
> (Group)}}.
> We can also look at this issue from a different angle: A user with {{Read}} 
> access to a group can describe the group, but the same user would not see 
> anything when listing groups (assuming there is no {{Describe}} access to the 
> cluster). It makes more sense for this user to be able to list all groups 
> s/he can already describe.
> It would be great to know if any user is relying on the existing behavior 
> (listing all consumer groups using a {{Describe (Cluster)}} ACL).



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

Reply via email to