Description
The code related to this issue is in AccessController.java:permissionGranted().
When creating audit logs, that method will do one of the following:
- grant access, create audit log with table name only
- deny access because of table permission, create audit log with table name only
- deny access because of column family / qualifier permission, create audit log with specific family / qualifier
So, in the case where more than one column family and/or qualifier are in the same request, there will be a loss of information. Even in the case where only one column family and/or qualifier is involved, information may be lost.
It would be better if this behavior consistently included all the information in the request; regardless of access being granted or denied, and regardless which permission caused the denial, the column family and qualifier info should be part of the audit log message.
Attachments
Attachments
Issue Links
- depends upon
-
HBASE-7518 Move AuthResult out of AccessController
- Closed
- relates to
-
HBASE-6096 AccessController v2
- Closed