Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-8426

Provide access to session from resource handler/provider

    XMLWordPrintableJSON

Details

    Description

      There should be a way to get access to the web server's session data from a (REST API) resource handler.

      This will allow a resource handler to access information such as a session encryption key that may be used to encrypt data during that session. An example of this would be when performing Kerberos-related activities, the following flow can occur:

      1. Session encryption key is created
      2. User uploads KDC administrator credentials
      3. administrator credential are encrypted using the session encryption key and persisted - maybe on disk, maybe in the Ambari database
      4. For every Kerberos administration action that needs to occur during that session, the administrative credentials may be loaded into memory, decrypted, used, and removed from memory
      5. When the session terminates, the encryption key is lost and the persisted administrator credentials become lost

      Attachments

        Issue Links

          Activity

            People

              tbeerbower Tom Beerbower
              rlevas Robert Levas
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: