ranger-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Abhay Kulkarni <akulka...@hortonworks.com>
Subject Re: Review Request 65950: Add support to allow clients to access resource permissions stored in Ranger
Date Wed, 07 Mar 2018 23:31:54 GMT

-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/65950/#review198831
-----------------------------------------------------------




agents-common/src/main/java/org/apache/ranger/plugin/policyevaluator/RangerDefaultPolicyEvaluator.java
Line 384 (original), 384 (patched)
<https://reviews.apache.org/r/65950/#comment279074>

    Please consider adding another method with a diffrent signature to get list of RangerPolicyItemEvaluators,
instead of changing signature and implementation of this critical method.
    
    Signature of new method may look like:
    
    List<RangerPolicyItemEvaluator> getDeterminingPolicyItems(String user, Set<String>
userGroups, List<String> accessType);
    
    Then have the caller provide list of all available hbase accessTypes - they can be figured
out from hbase Service-definition).
    
    Method implementation may call getDeterminingPolicyItem for each accessType to build a
list.
    
    This will isolate current implementation from hbase specific changes.
    
    Thanks!


- Abhay Kulkarni


On March 7, 2018, 2:13 p.m., Ankit Singhal wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/65950/
> -----------------------------------------------------------
> 
> (Updated March 7, 2018, 2:13 p.m.)
> 
> 
> Review request for ranger and Ramesh Mani.
> 
> 
> Bugs: RANGER-1958
>     https://issues.apache.org/jira/browse/RANGER-1958
> 
> 
> Repository: ranger
> 
> 
> Description
> -------
> 
> RANGER-1958 [HBase] Implement getUserPermissions API of AccessControlService.Interface
to allow clients to access HBase permissions stored in Ranger
> 
> 
> Diffs
> -----
> 
>   agents-common/src/main/java/org/apache/ranger/plugin/policyengine/RangerPolicyEngine.java
189dc2c 
>   agents-common/src/main/java/org/apache/ranger/plugin/policyengine/RangerPolicyEngineImpl.java
f8241c5 
>   agents-common/src/main/java/org/apache/ranger/plugin/policyengine/RangerResourceInfo.java
PRE-CREATION 
>   agents-common/src/main/java/org/apache/ranger/plugin/policyevaluator/RangerDefaultPolicyEvaluator.java
2b66c70 
>   agents-common/src/main/java/org/apache/ranger/plugin/policyevaluator/RangerPolicyEvaluator.java
7a890b8 
>   agents-common/src/main/java/org/apache/ranger/plugin/service/RangerBasePlugin.java
aad7834 
>   hbase-agent/src/main/java/org/apache/ranger/authorization/hbase/RangerAuthorizationCoprocessor.java
12b675b 
>   hbase-agent/src/test/java/org/apache/ranger/authorization/hbase/HBaseRangerAuthorizationTest.java
665640f 
>   hbase-agent/src/test/java/org/apache/ranger/authorization/hbase/TestPolicyEngine.java
9f0e5ac 
>   hbase-agent/src/test/resources/policyengine/test_policyengine_hbase.json f563c28 
> 
> 
> Diff: https://reviews.apache.org/r/65950/diff/1/
> 
> 
> Testing
> -------
> 
> Unit testing is done
> 
> 
> Thanks,
> 
> Ankit Singhal
> 
>


Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message