Hello Zoltan Chovan, Alexey Serbin,
I'd like you to do a code review. Please visit
http://gerrit.cloudera.org:8080/24826
to review the following change.
Change subject: [rpc] Add proxy user identity support
......................................................................
[rpc] Add proxy user identity support
Enable a client to act on behalf of another user (KUDU-3586), following
the semantics of Hadoop's SASL proxyuser protocol: for impersonation,
USER is the impersonated (effective) user and AUTHNAME is the real user.
Client side:
* UserCredentials gains an optional effective_user field that is empty
by default and participates in HashCode()/operator==() so that
connections with different effective users are never conflated.
AuthenticationCredentialsPB gains a matching field so a proxied
identity survives credential export and import (e.g. from a Spark
driver to its executors).
* ClientNegotiation registers a SASL_CB_USER callback when an effective
user is configured, sending it as the SASL authorization identity
while still authenticating as the real user.
Server side:
* RemoteUser tracks both identities: real_username_ is established by
the authentication mechanism (SASL_AUTHUSER) while username_ remains
the effective user and defaults to the real one. All downstream
authorization and ownership checks keep using username_, while logs
and RPC diagnostics retain both identities for auditability.
* After SASL completes, the server reads both identities and fails the
negotiation if the authentication identity is missing: falling back
to the authorization identity would make a proxy request appear to be
a direct login and bypass proxy authorization.
* The effective user carried in the (deprecated) ConnectionContextPB
user info is cross-checked against the SASL authorization identity
for proxy sessions, rejecting clients that claim a different user at
the connection-context layer. For regular connections the field is
ignored, as it was by older versions of Kudu.
* The messenger carries a ProxyUserAuthorizer and the negotiation
authorizes a proxy request against the real user, the effective user,
the authentication type, and the peer address. Connections whose
authorization identity matches their authentication identity skip the
checks entirely.
A client with an effective user configured also stops using cached
authentication tokens: tokens are bound to their original user and
cannot be used to impersonate another user.
Change-Id: I3f26169f14552d2566272a32525156cd30627aa3
---
M src/kudu/rpc/client_negotiation.cc
M src/kudu/rpc/client_negotiation.h
M src/kudu/rpc/messenger.cc
M src/kudu/rpc/messenger.h
M src/kudu/rpc/negotiation.cc
M src/kudu/rpc/remote_user.cc
M src/kudu/rpc/remote_user.h
M src/kudu/rpc/rpc_header.proto
M src/kudu/rpc/server_negotiation.cc
M src/kudu/rpc/server_negotiation.h
M src/kudu/rpc/user_credentials.cc
M src/kudu/rpc/user_credentials.h
12 files changed, 209 insertions(+), 24 deletions(-)
git pull ssh://gerrit.cloudera.org:29418/kudu refs/changes/26/24826/1
--
To view, visit http://gerrit.cloudera.org:8080/24826
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings
Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I3f26169f14552d2566272a32525156cd30627aa3
Gerrit-Change-Number: 24826
Gerrit-PatchSet: 1
Gerrit-Owner: mintao <[email protected]>
Gerrit-Reviewer: Alexey Serbin <[email protected]>
Gerrit-Reviewer: Zoltan Chovan <[email protected]>