[
https://issues.apache.org/jira/browse/ATLAS-5418?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18119181#comment-18119181
]
ASF subversion and git services commented on ATLAS-5418:
--------------------------------------------------------
Commit 13414818896c2efb902b1c14ddb23bfe69f97b9d in atlas's branch
refs/heads/master from sheetalshah1007
[ https://gitbox.apache.org/repos/asf?p=atlas.git;h=134148188 ]
ATLAS-5418: Enforce entity read check on v1 entity audit API (#770)
> v1 entity audit endpoint bypasses entity read authorization
> -----------------------------------------------------------
>
> Key: ATLAS-5418
> URL: https://issues.apache.org/jira/browse/ATLAS-5418
> Project: Atlas
> Issue Type: Bug
> Components: atlas-core
> Reporter: Sheetal Shah
> Assignee: Sheetal Shah
> Priority: Major
> Time Spent: 20m
> Remaining Estimate: 0h
>
> h3. Summary
> v1 entity audit API missing ENTITY_READ check allows unprivileged users to
> read audit history
> ----
> h3. Description
> The v1 endpoint {{GET /api/atlas/entities/\{guid}/audit}} returns entity
> audit events without performing entity read authorization. It reads the audit
> repository directly after Spring Security authentication only.
> The v2 endpoint {{GET /api/atlas/v2/entity/\{guid}/audit}} enforces the same
> entity read access as other v2 read paths (including a path for purged
> entities via audit metadata).
> An authenticated user who is denied entity read on v2 can still retrieve full
> v1 audit history (including attribute snapshots in event details) if they
> know the entity GUID.
> Impact: Unauthorized disclosure of metadata change history and historical
> attribute values to any logged-in user without ENTITY_READ on that entity.
> Affected code (reference): {{EntityResource.getAuditEvents()}} — no
> {{AtlasAuthorizationUtils}} / entity read check before
> {{{}entityAuditRepository.listEvents(){}}}. v2:
> {{EntityREST.getAuditEvents()}} performs authorization before listing events.
> ----
> h3. Environment (example — adjust as needed)
> * Apache Atlas 3.0.0-SNAPSHOT (local deploy)
> * File authentication + simple authorizer
> * Config under {{{}{ATLAS_HOME}/conf/{}}}:
> ** {{{}atlas-application.properties{}}}:
> {{{}atlas.authentication.method.file=true{}}},
> {{atlas.authorizer.impl=simple}}
> ** {{{}users-credentials.properties{}}}: {{admin}} and unprivileged test
> user {{bob}}
> ** {{{}atlas-simple-authz-policy.json{}}}: {{admin}} in {{{}userRoles{}}};
> {{bob}} not in {{userRoles}}
> ----
> h3. Steps to reproduce
> # Configure auth and authorization
> ** In {{{}conf/atlas-application.properties{}}}, enable file auth and simple
> authorizer (see above).
> ** In {{{}conf/users-credentials.properties{}}}, ensure {{admin}} exists and
> add a test user, e.g.
> {{bob=NOBODY::<sha256-hex-of-password>}}
> (generate with {{{}echo -n 'bobpass' | shasum -a 256{}}}).
> ** In {{{}conf/atlas-simple-authz-policy.json{}}}, map only {{admin}} to
> {{ROLE_ADMIN}} in {{{}userRoles{}}}. Do not add {{bob}} to {{userRoles}} or
> {{{}groupRoles{}}}.
> ** Restart Atlas.
> # Create a test entity (as admin)
> {{export ATLAS=http://localhost:21000
> QN="triage_$(date +%s)@cl1"
> curl -s -u admin:<admin-password> -H 'Content-Type: application/json' \
> -X POST "$ATLAS/api/atlas/v2/entity/bulk" \
> -d
> "\{\"entities\":[{\"typeName\":\"hive_db\",\"attributes\":{\"qualifiedName\":\"${QN}\",\"name\":\"triage\",\"clusterName\":\"cl1\"}}]}"}}
> Note the returned GUID.
> # Confirm bob is denied on v2 read paths
> {{export GUID=<entity-guid>
> BOB=bob:<bob-password>
> curl -s -o /dev/null -w '%\{http_code}\n' -u $BOB
> "$ATLAS/api/atlas/v2/entity/guid/$GUID"
> curl -s -o /dev/null -w '%\{http_code}\n' -u $BOB
> "$ATLAS/api/atlas/v2/entity/$GUID/audit?count=20"}}
> Observed: HTTP 403 for both.
> # Call v1 audit as bob
> {{curl -s -o /dev/null -w '%\{http_code}\n' -u $BOB
> "$ATLAS/api/atlas/entities/$GUID/audit?count=20"}}
> Observed: HTTP 200 with audit events in the response body.
> # Optional control — unauthenticated v1 audit
> {{curl -s -o /dev/null -w '%\{http_code}\n'
> "$ATLAS/api/atlas/entities/$GUID/audit?count=20"}}
> Observed: HTTP 401.
> ----
> h3. Expected result
> All entity audit read paths should require ENTITY_READ (same as v2). Bob
> should receive 403 on v1 audit when v2 entity read and v2 audit return 403.
> ----
> h3. Actual result
> v1 audit returns 200 to bob while v2 entity read and v2 audit return 403.
> Only authentication is enforced on v1 audit, not entity read authorization.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)