Uploaded image for project: 'IMPALA'
  1. IMPALA
  2. IMPALA-11684

Only use LDAP group filter when there is no authorization provider

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • Backend, Frontend, Security
    • None
    • ghx-label-14

    Description

      Impala applies the LDAP group filters during authentication which can deny users even from accessing Impala. We should reconsider this decision because authenticating based on groups falls into a grey area with authorization. Users without group privileges could be authenticated successfully and the authorization provider should handle what they can see.

      Attachments

        Activity

          People

            tmate Tamas Mate
            tmate Tamas Mate
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: