hadoop-common-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Benoy Antony (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (HADOOP-10679) Authorize webui access using ServiceAuthorizationManager
Date Tue, 10 Jun 2014 22:53:02 GMT

     [ https://issues.apache.org/jira/browse/HADOOP-10679?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Benoy Antony updated HADOOP-10679:
----------------------------------

    Description: 
Currently accessing Hadoop via RPC can be authorized using _ServiceAuthorizationManager_.
But there is no uniform authorization of the HTTP access. Some of the servlets check for admin
privilege. 
This creates an inconsistency of authorization between access via RPC vs HTTP. 

The fix is to enable authorization of the webui access also using _ServiceAuthorizationManager_.




  was:
Currently accessing Hadoop via RPC can be authorized using _ServiceAuthorizationManager_.
But there is no uniform authorization of the HTTP access. Some of the servlets check for admin
privilege. 
This creates an inconsistency of authorization between access via RPC vs HTTP. 

The fix is to enable authorization of the webui access using _ServiceAuthorizationManager_.





> Authorize webui access using ServiceAuthorizationManager
> --------------------------------------------------------
>
>                 Key: HADOOP-10679
>                 URL: https://issues.apache.org/jira/browse/HADOOP-10679
>             Project: Hadoop Common
>          Issue Type: Sub-task
>          Components: security
>            Reporter: Benoy Antony
>            Assignee: Benoy Antony
>
> Currently accessing Hadoop via RPC can be authorized using _ServiceAuthorizationManager_.
But there is no uniform authorization of the HTTP access. Some of the servlets check for admin
privilege. 
> This creates an inconsistency of authorization between access via RPC vs HTTP. 
> The fix is to enable authorization of the webui access also using _ServiceAuthorizationManager_.




--
This message was sent by Atlassian JIRA
(v6.2#6252)

Mime
View raw message