Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-3828

Fine-grained Access Control over nested structures

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 3.0.0, 2.4.0
    • plugins, Ranger
    • None

    Description

      It would be nice to be able to do fine-grained access control (FGA) over nested structures, e.g., the JSON responses of API calls.  This requires the individual attributes in a JSON object to be first-class metadata objects which can be tagged and on which policies can be written.  We have built a plugin and the corresponding Apache Atlas metadata structures and tagsync-mapper to support TBAC/RBAC/ABAC FGA over JSON structures.   Our instigating use case was FGA over the JSON responses of API calls, but this plugin has potential value anywhere FGA over the individual attributes of nested structures is needed, eg JSON messages read from Kafka topics.

       

      Attachments

        1. image003.png
          52 kB
          Eckman, Barbara
        2. image002.png
          369 kB
          Eckman, Barbara
        3. image001.png
          401 kB
          Eckman, Barbara

        Activity

          People

            barbara Barbara Eckman
            barbara Barbara Eckman
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: