Uploaded image for project: 'HCatalog'
  1. HCatalog
  2. HCATALOG-433

user can describe table though no rights given; using HdfsAuthorizationProvider

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Invalid
    • 0.4.1
    • None
    • security
    • None

    Description

      With hive.security.authorization.manager set to HdfsAuthorizationProvider
      and a database with a table, where both database directory and the inclosed
      table directory had permissions:

      drwx------ - user1 users

      the user 'user2' could do both a 'show tables' on the database and a
      'described formatted' on the table.

      Both of these operations correctly failed with HCatalog 0.2.

      Attachments

        Activity

          People

            Unassigned Unassigned
            esoren Egil Sorensen
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: