Github user tgravescs commented on a diff in the pull request:
https://github.com/apache/spark/pull/12760#discussion_r61892471
--- Diff: core/src/test/scala/org/apache/spark/SecurityManagerSuite.scala
---
@@ -166,6 +284,56 @@ class SecurityManagerSuite extends SparkFunSuite with
ResetSystemProperties {
assert(securityManager.checkModifyPermissions("user8") === true)
}
+ test("set security with * in acls for groups") {
+ val conf = new SparkConf
+ conf.set("spark.ui.acls.enable", "true")
+ conf.set("spark.admin.acls.groups", "group4,group5")
+ conf.set("spark.ui.view.acls.groups", "*")
+ conf.set("spark.modify.acls.groups", "group6")
+
+ val securityManager = new SecurityManager(conf)
+ assert(securityManager.aclsEnabled() === true)
+
+ // check for viewAclsGroups with *
+ assert(securityManager.checkUIViewPermissions("user1") === true)
+ assert(securityManager.checkUIViewPermissions("user2") === true)
+ assert(securityManager.checkModifyPermissions("user1") === false)
+ assert(securityManager.checkModifyPermissions("user2") === false)
+
+ // check for modifyAcls with *
+ securityManager.setModifyAclsGroups("*")
+ securityManager.setViewAclsGroups("group6")
+ assert(securityManager.checkUIViewPermissions("user1") === false)
+ assert(securityManager.checkUIViewPermissions("user2") === false)
+ assert(securityManager.checkModifyPermissions("user1") === true)
+ assert(securityManager.checkModifyPermissions("user2") === true)
+
+ // check for adminAcls with *
+ securityManager.setAdminAclsGroups("group9,*")
+ securityManager.setModifyAclsGroups("group4,group5")
+ securityManager.setViewAclsGroups("group6,group7")
+ assert(securityManager.checkUIViewPermissions("user5") === true)
+ assert(securityManager.checkUIViewPermissions("user6") === true)
+ assert(securityManager.checkModifyPermissions("user7") === true)
+ assert(securityManager.checkModifyPermissions("user8") === true)
+ }
+
+ test("security for groups default behavior") {
+ // no groups or userToGroupsMapper is provided
--- End diff --
assume you mean is not provided. Also add a test for setting it to a bogus
value
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]