Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-2642

Grant/Revoke REST invocations by non-service users should not specify resource owner

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • master
    • master, 2.1.0
    • Ranger
    • None

    Description

      If Grant/Revoke REST API is invoked by a user which is not a admin or not listed in policy.grantrevoke.auth.users config parameter value, then resource being granted permission to should not specify ownership information. Otherwise, such user may be able to modify a resource for which it does not have delegated-admin privilege.

      Attachments

        Activity

          People

            abhayk Abhay Kulkarni
            abhayk Abhay Kulkarni
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: