Uploaded image for project: 'Apache Storm'
  1. Apache Storm
  2. STORM-349

(Security) ui actions should have nimbus like authroization

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 0.10.0
    • storm-core

    Description

      The UI provides APIs to kill, rebalance, ... a topology. For security we originally took the route to optionally disable these, but ideally the UI server would load an IAuthorizer instance like nimbus, and check if the user is allowed to perform that operation before doing it on behalf of the user.

      This should be fairly straight forward but may require some glue code like is being used in the drpc server for its web interface.

      Attachments

        Activity

          People

            sriharsha Harsha
            revans2 Robert Joseph Evans
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: