Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-1090

Revoke command with grant option does not disable delegated admin permission for users/groups in the corresponding policy

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 0.6.0
    • Fix Version/s: 0.7.0, 0.6.3
    • Component/s: Ranger
    • Labels:
      None

      Description

      Pre-requisites Steps :
      Install Ranger, Hive Component and enable Ranger for Hive component.

      Steps to Reproduce:
      Execute grant command(with grant option) in hive; at Ranger end it will create policy with corresponds details specified in the grant command like resources, permission, users, groups and also enables delegatedAdmin permission(set to true).
      Sample : grant select, UPDATE ON TABLE xatestgr.testtable to USER user1 with grant option;
      Now execute revoke command with 'revoke grant option' from hive; at Ranger end it will update policy with correct info as specified in the revoke command like resources, users/groups, access permissions but it does not change delegatedAdmin permission(back to false)
      Sample : revoke grant option for select, create, update, drop ON TABLE xatestgr.testtable FROM USER user1;

      Expected behaviour :
      When run revoke command with 'revoke grant option' it should change delegated admin permission.

        Attachments

        1. RANGER-1090-3.patch
          5 kB
          Pradeep Agrawal
        2. RANGER-1090-2.patch
          30 kB
          Pradeep Agrawal

          Activity

            People

            • Assignee:
              pradeep.agrawal Pradeep Agrawal
              Reporter:
              pradeep.agrawal Pradeep Agrawal
            • Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: