Details
-
New Feature
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
1.3.0
-
None
-
None
Description
Currently the finest grain of privilege is at the table/view level. This leads to the unwieldy scenario where a different view has to be created for each combination of columns that need to be restricted. With column level privileges this would not be required.
In the policy file column privileges might potentially look like:
server=server1->db=default->table=employees->column=salary->action=select
Attachments
Attachments
Issue Links
- contains
-
SENTRY-389 Database implementation for column
- Resolved
-
SENTRY-390 Extend Thrift API to support column-level privilege
- Resolved
-
SENTRY-391 Extend sentrystore query for column level privilege
- Resolved
-
SENTRY-392 Authorization for column level security
- Resolved
-
SENTRY-393 Grant/Revoke and Show Grant info support for column level privilege
- Resolved
-
SENTRY-394 PolicyFile and ConfigImport support for column level privilege
- Resolved
-
SENTRY-426 Add upgrade scripts for column level privileges
- Resolved
-
SENTRY-847 [column level privilege] if grant column level privilege to user, show columns in table shouldn't require extra table level privilege
- Resolved
- incorporates
-
SENTRY-754 Support column level privileges on views
- Open
-
SENTRY-753 Add documentation for Column level authorization
- Resolved
- is blocked by
-
HIVE-7932 It may cause NP exception when add accessed columns to ReadEntity
- Resolved
-
SENTRY-509 upgrade HIVE version to 0.13.1-cdh5.3.0-SNAPSHOT in SENTRY
- Resolved
-
HIVE-7730 Extend ReadEntity to add accessed columns from query
- Closed
- is depended upon by
-
SENTRY-491 Column privilege should filter the unauthorized columns in metadata listing
- Open
- is related to
-
SENTRY-531 Add column authorization for metadata read protection
- In Progress
- relates to
-
SENTRY-389 Database implementation for column
- Resolved
-
SENTRY-756 Blacklist columns instead of whitelist in column level privileges
- Open
-
SENTRY-755 HDFS access of data files should be disabled for user with privileges only on some columns
- Resolved
-
SENTRY-844 Add tests for cases: Column-level privileges are updated when table columns are dropped, changed or replaced (i.e., using an ALTER TABLE stmt)
- Open
-
SENTRY-758 Add test cases for partition columns with column level privileges
- Resolved
-
SENTRY-742 Add describe, show/compute stats tests for column level privileges
- Resolved
- links to