This is an automated email from the ASF dual-hosted git repository.
rzo1 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/storm.git
The following commit(s) were added to refs/heads/master by this push:
new b8c71da61 Evaluate nimbus.groups when nimbus.users is empty (#8998)
b8c71da61 is described below
commit b8c71da61c396693e02c0e7add325992721c4fe0
Author: Richard Zowalla <[email protected]>
AuthorDate: Sun Aug 23 19:03:35 2026 +0200
Evaluate nimbus.groups when nimbus.users is empty (#8998)
---
.../auth/authorizer/SimpleACLAuthorizer.java | 6 ++-
.../auth/authorizer/SimpleACLAuthorizerTest.java | 51 ++++++++++++++++++++++
2 files changed, 56 insertions(+), 1 deletion(-)
diff --git
a/storm-client/src/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizer.java
b/storm-client/src/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizer.java
index 1e088752f..3e93a268a 100644
---
a/storm-client/src/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizer.java
+++
b/storm-client/src/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizer.java
@@ -157,7 +157,11 @@ public class SimpleACLAuthorizer implements IAuthorizer {
}
if (userCommands.contains(operation)) {
- return nimbusUsers.size() == 0 || nimbusUsers.contains(user) ||
checkUserGroupAllowed(userGroups, nimbusGroups);
+ // Only an empty nimbus.users AND an empty nimbus.groups means no
restriction is configured.
+ if (nimbusUsers.size() == 0 && nimbusGroups.size() == 0) {
+ return true;
+ }
+ return nimbusUsers.contains(user) ||
checkUserGroupAllowed(userGroups, nimbusGroups);
}
if (topoCommands.contains(operation)) {
diff --git
a/storm-client/test/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizerTest.java
b/storm-client/test/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizerTest.java
index 15f4b9bbe..72c0e8a77 100644
---
a/storm-client/test/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizerTest.java
+++
b/storm-client/test/jvm/org/apache/storm/security/auth/authorizer/SimpleACLAuthorizerTest.java
@@ -225,6 +225,57 @@ public class SimpleACLAuthorizerTest {
assertTrue(authorizer.permit(new ReqContext(supervisorUser),
"fileDownload", new HashMap<>()));
}
+ @Test
+ @DisabledOnOs(OS.WINDOWS)
+ public void SimpleACLNimbusGroupAuthTest() {
+ Subject userA = createSubject("user-a");
+ Subject userInGroup = createSubject("user-in-readonly-group");
+ Subject userB = createSubject("user-b");
+
+ // neither nimbus.users nor nimbus.groups is set, so there is no
restriction
+ IAuthorizer authorizer = prepareNimbusAuthorizer(null, null);
+ assertTrue(authorizer.permit(new ReqContext(userA), "submitTopology",
new HashMap<>()));
+ assertTrue(authorizer.permit(new ReqContext(userInGroup),
"submitTopology", new HashMap<>()));
+ assertTrue(authorizer.permit(new ReqContext(userB), "getClusterInfo",
new HashMap<>()));
+
+ // only nimbus.users is set
+ authorizer =
prepareNimbusAuthorizer(Collections.singletonList("user-a"), null);
+ assertTrue(authorizer.permit(new ReqContext(userA), "submitTopology",
new HashMap<>()));
+ assertFalse(authorizer.permit(new ReqContext(userInGroup),
"submitTopology", new HashMap<>()));
+ assertFalse(authorizer.permit(new ReqContext(userB), "getClusterInfo",
new HashMap<>()));
+
+ // only nimbus.groups is set
+ authorizer = prepareNimbusAuthorizer(null,
Collections.singletonList("group-readonly"));
+ assertTrue(authorizer.permit(new ReqContext(userInGroup),
"submitTopology", new HashMap<>()));
+ assertFalse(authorizer.permit(new ReqContext(userA), "submitTopology",
new HashMap<>()));
+ assertFalse(authorizer.permit(new ReqContext(userB), "fileUpload", new
HashMap<>()));
+ assertFalse(authorizer.permit(new ReqContext(userB), "getClusterInfo",
new HashMap<>()));
+
+ // both nimbus.users and nimbus.groups are set
+ authorizer =
prepareNimbusAuthorizer(Collections.singletonList("user-a"),
Collections.singletonList("group-readonly"));
+ assertTrue(authorizer.permit(new ReqContext(userA), "submitTopology",
new HashMap<>()));
+ assertTrue(authorizer.permit(new ReqContext(userInGroup),
"submitTopology", new HashMap<>()));
+ assertFalse(authorizer.permit(new ReqContext(userB), "submitTopology",
new HashMap<>()));
+ }
+
+ private IAuthorizer prepareNimbusAuthorizer(Collection<String>
nimbusUsers, Collection<String> nimbusGroups) {
+ Map<String, Object> clusterConf = ConfigUtils.readStormConfig();
+ clusterConf.put(Config.STORM_GROUP_MAPPING_SERVICE_PROVIDER_PLUGIN,
+
SimpleACLTopologyReadOnlyGroupAuthTestMock.class.getName());
+
+ if (nimbusUsers != null) {
+ clusterConf.put(Config.NIMBUS_USERS, new HashSet<>(nimbusUsers));
+ }
+
+ if (nimbusGroups != null) {
+ clusterConf.put(Config.NIMBUS_GROUPS, new HashSet<>(nimbusGroups));
+ }
+
+ IAuthorizer authorizer = new SimpleACLAuthorizer();
+ authorizer.prepare(clusterConf);
+ return authorizer;
+ }
+
@Test
@DisabledOnOs(OS.WINDOWS)
public void SimpleACLTopologyReadOnlyUserAuthTest() {