Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-3142

Access control based on groups not working for presto plugin

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 2.1.0
    • None
    • plugins
    • None
    • ranger-2.1.0-presto-plugin.tar.gz
      presto-server-347.tar.gz

    Description

      I'm using ranger-2.1.0 for access control in prestosql-347.

      A policy with user list in 'allow conditions' works i.e. if I connect to presto with a user in the allowed list, my query returns the expected results.

      But instead of users, if I use group in the policy and try accessing presto with a user belonging to that group, then I'm denied access.

      %presto
      show tables in default
      
      Query failed (#20210106_032741_00000_dddsy): Access Denied: Cannot access catalog hive
      

      Attachments

        1. image-2021-01-29-19-53-59-145.png
          11 kB
          sooyeon shin
        2. image-2021-01-29-19-54-02-248.png
          13 kB
          sooyeon shin
        3. image-2021-01-29-19-54-28-329.png
          19 kB
          sooyeon shin
        4. image-2021-01-29-19-54-50-303.png
          68 kB
          sooyeon shin
        5. image-2021-01-29-19-55-01-685.png
          50 kB
          sooyeon shin
        6. image-2021-01-29-19-59-42-929.png
          39 kB
          sooyeon shin
        7. image-2021-01-29-20-00-54-796.png
          103 kB
          sooyeon shin

        Activity

          People

            Unassigned Unassigned
            anchal.agarwal Anchal Agarwal
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated: