Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-16449 Revisit AccessController audit logging
  3. HBASE-16311

Audit log for delete snapshot operation is missing in case of snapshot owner deleting the same

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • 2.0.0
    • 1.4.0, 2.0.0
    • snapshots
    • None
    • Reviewed

    Description

      1. Audit log seems to be left as a TODO task in AccessController.java:

        @Override
        public void preDeleteSnapshot(final ObserverContext<MasterCoprocessorEnvironment> ctx,
            final SnapshotDescription snapshot) throws IOException {
          if (SnapshotDescriptionUtils.isSnapshotOwner(snapshot, getActiveUser())) {
            // Snapshot owner is allowed to delete the snapshot
            // TODO: We are not logging this for audit
          } else {
            requirePermission("deleteSnapshot", Action.ADMIN);
          }
        }
      

      2. Also, snapshot name is not getting logged in the audit logs.

      Attachments

        1. HBASE-16311-V4-branch-1.patch
          5 kB
          Jerry He
        2. HBASE-16311-V4.patch
          4 kB
          Yi Liang
        3. HBASE-16311-V3.patch
          4 kB
          Yi Liang
        4. HBASE-16311-V2.patch
          3 kB
          Yi Liang
        5. HBASE-16311-V1.patch
          3 kB
          Yi Liang

        Activity

          People

            easyliangjob Yi Liang
            a72877 Abhishek Kumar
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: