hive-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Thejas M Nair (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HIVE-7533) sql std auth - set authorization privileges for tables when created from hive cli
Date Fri, 15 Aug 2014 22:21:19 GMT

    [ https://issues.apache.org/jira/browse/HIVE-7533?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14099269#comment-14099269
] 

Thejas M Nair commented on HIVE-7533:
-------------------------------------

Looks like this has broken the build. One of the test files committed in a recent patch fails
to compile. 
I had run only the auth*.q tests to validate, and had not run the ql/ dir tests.
Will fix in few minutes.


> sql std auth - set authorization privileges for tables when created from hive cli
> ---------------------------------------------------------------------------------
>
>                 Key: HIVE-7533
>                 URL: https://issues.apache.org/jira/browse/HIVE-7533
>             Project: Hive
>          Issue Type: Bug
>          Components: Authorization, SQLStandardAuthorization
>            Reporter: Thejas M Nair
>            Assignee: Thejas M Nair
>             Fix For: 0.14.0
>
>         Attachments: HIVE-7533.1.patch, HIVE-7533.2.patch, HIVE-7533.3.patch
>
>
> As SQL standard authorization mode is not available from hive-cli, the default permissions
on table for the table owner are not being set, when the table is created from hive-cli.
> It should be possible set the sql standards based authorization as the authorizer for
hive-cli, which would update the configuration appropriately. 
> hive-cli data access is actually controlled by hdfs, not the authorization policy. As
a result, using sql std auth from hive-cli for authorization would lead to a false sense of
security. To avoid this, hive-cli users will have to keep the authorization disabled on hive-cli
 (in case of sql std auth). But this would affect only authorization checks, not configuration
updates by the authorizer.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Mime
View raw message