Uploaded image for project: 'Zeppelin'
  1. Zeppelin
  2. ZEPPELIN-3176

Interpreter binding for a note can be changed by readers of that note

    Details

    • Type: Bug
    • Status: Open
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 0.7.3
    • Fix Version/s: None
    • Component/s: front-end
    • Labels:
    • Environment:

      Docker deployment of Zeppelin 0.7.3  (docker hub: apache/zeppelin:0.7.3)

      Description

      Readers of a note change change the interpreter binding of the note. This should not be possible.

      To reproduce:

      1. Create a note with a particular user account, say user1
      2. Open the 'interpreter binding' options and ensure that a few are selected
      3. Using the note permissions dialog, make user1 the only owner and writer of that note, with the 'Readers' field blank
      4. Log into Zeppelin as another user, say user2
      5. Open the note created in step1 and uncheck (remove) one ore more interpreters
      6. Click Save
      7. Check the note interpreter binding using user1 account

      You'll see that the interpreter bindings have been changed by the note reader user2

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              aerianis Andrew X
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: