Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-2405

Evaluation of Ranger policies targeted to valid but partial resources

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: master
    • Fix Version/s: master
    • Component/s: plugins, Ranger
    • Labels:
      None

      Description

      With RANGER-1781, Ranger supports resource policies with valid, but partial hierarchies specified as the resource. However, during policy evaluation, a partial hierarchy is treated as a complete hierarchy with the unspecified part of the resource hierarchy as having been specified with an all-matching wildcard value (that is, as an asterisk). This leads to such policy matching an accessed resource which has more resource levels than in the policy, and is more permissive than the policy specification.

        Attachments

          Activity

            People

            • Assignee:
              abhayk Abhay Kulkarni
              Reporter:
              abhayk Abhay Kulkarni
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: