Uploaded image for project: 'Sentry (Retired)'
  1. Sentry (Retired)
  2. SENTRY-541

Seperate udfuri privilege from anyPrivilege model

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.5.0
    • None
    • None

    Description

      Currently both 'use db' and 'create function' use anyPrivilege, I think 'create funciton' can own itself's privilege which operation scope is ‘URI’ rather than 'CONNECT'. Because the test case in TestHiveAuthzBindings.testValidateCreateFunctionForAdmin make me very confused, we must have column level privilege so that we can pass the authorize. And this jira also block SENTRY-505.

      Attachments

        1. SENTRY-541.001.patch
          7 kB
          Xiaomeng Huang
        2. SENTRY-541.002.patch
          8 kB
          Xiaomeng Huang
        3. SENTRY-541.003.patch
          8 kB
          Xiaomeng Huang

        Issue Links

          Activity

            People

              Huang Xiaomeng Xiaomeng Huang
              Huang Xiaomeng Xiaomeng Huang
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Slack

                  Issue deployment