Uploaded image for project: 'Zeppelin'
  1. Zeppelin
  2. ZEPPELIN-3509

Notebook Authorization not working

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Not A Problem
    • Affects Version/s: 0.8.0
    • Fix Version/s: None
    • Component/s: security
    • Labels:
      None

      Description

      Dear Team,

      In zeppelin 0.8.0 release Notebook authorization not working properly.  

      Authorization Setting for User Notebook Note 1

      User1 -> Runner

      admin -> Owner

      User1 able to update notebook permission for all (owner, runner, reader, writer )

      Steps to reproduce:

      1. Login as admin and give access to user 1 as a runner, shown in attached image step
      2. Login as user1 open Note 1 here user 1 is able to open and update the notebook permissions shown in attached image step 2a.
      3. User 1 changed Owner rights from admin to user1 and save successfully shown in attached image 2b.
      4. Login as admin, open Note 1 notebook here we can see the Owner rights are changed from admin to user1 shown in attached image Step 3.

      According to my understanding, User1 should not able to open Notebook permission button. I also attached my shiro.ini file.

       

        Attachments

        1. Step_1.PNG
          70 kB
          Madiha Khalid
        2. shiro.ini
          5 kB
          Madiha Khalid
        3. Step_2b.PNG
          50 kB
          Madiha Khalid
        4. Step_3.PNG
          70 kB
          Madiha Khalid
        5. Step_2a.PNG
          90 kB
          Madiha Khalid

          Activity

            People

            • Assignee:
              prabhjyotsingh Prabhjyot Singh
              Reporter:
              mkhalid Madiha Khalid
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: