Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-124

Fix the OR semantics in AclAuthz

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 0.3.0
    • Server
    • None

    Description

      Wildcard '*' characters in the ACL definition for acl.processing.mode of OR provide inappropriate access to the protected resource. Change to effective disregard wildcard acls by denying access for them. The fact that we are ORing them will result in the desired protection.

      Attachments

        Activity

          People

            lmccay Larry McCay
            lmccay Larry McCay
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: