accumulo-notifications mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Mike Drob (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (ACCUMULO-891) Authorizations not actually immutable
Date Tue, 11 Dec 2012 05:31:21 GMT

    [ https://issues.apache.org/jira/browse/ACCUMULO-891?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13528683#comment-13528683
] 

Mike Drob commented on ACCUMULO-891:
------------------------------------

This is easy to fix by calling {{asReadOnlyBuffer}} on each {{ByteBuffer}}, However, {{getAuthorizations}}
looks like it suffers from the same issue of returning an immutable list but allowing changes
to write through. Not sure if there's a good solution to that one.
                
> Authorizations not actually immutable
> -------------------------------------
>
>                 Key: ACCUMULO-891
>                 URL: https://issues.apache.org/jira/browse/ACCUMULO-891
>             Project: Accumulo
>          Issue Type: Bug
>          Components: client
>    Affects Versions: 1.4.2
>            Reporter: Mike Drob
>              Labels: newbie
>         Attachments: AuthorizationsTest.java
>
>
> Instances of {{Authorizations}} are not actually immutable, despite the API making it
seem like they are. A user can make changes that will write-through to the backing data by
using the ByteBuffer getter.
> This is a potential issue if a trusted application acts as a connection broker between
accumulo and untrusted clients.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Mime
View raw message