[ 
https://issues.apache.org/jira/browse/KNOX-2215?focusedWorklogId=380616&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-380616
 ]

ASF GitHub Bot logged work on KNOX-2215:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 03/Feb/20 01:10
            Start Date: 03/Feb/20 01:10
    Worklog Time Spent: 10m 
      Work Description: lmccay commented on issue #251: KNOX-2215 - Token 
service should return a 401 response when the renew…
URL: https://github.com/apache/knox/pull/251#issuecomment-581200463
 
 
   I believe 403 is more appropriate but it should align with what hadoop does
   either way.
   
   On Sun, Feb 2, 2020, 6:09 PM Phil Zampino <[email protected]> wrote:
   
   > @risdenk <https://github.com/risdenk>, my rational for choosing 401 is
   > the definition from
   > https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html:
   >
   > 401: "If the request already included Authorization credentials, then the
   > 401 response indicates that *authorization* has been refused for those
   > credentials."
   >
   > 403: "The server understood the request, but is refusing to fulfill it.
   > Authorization will not help"
   >
   > So, in this case, the renewing/revoking user is *AUTHENTICATED*, but *NOT
   > AUTHORIZED* to perform the requested operation.
   >
   > —
   > You are receiving this because your review was requested.
   > Reply to this email directly, view it on GitHub
   > 
<https://github.com/apache/knox/pull/251?email_source=notifications&email_token=AARSNOFQJXD5A4CU3RDIHVTRA5HDXA5CNFSM4KONDIC2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEKSDUNI#issuecomment-581188149>,
   > or unsubscribe
   > 
<https://github.com/notifications/unsubscribe-auth/AARSNOHWEWZFDRUJ4KWISNLRA5HDXANCNFSM4KONDICQ>
   > .
   >
   
 
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
[email protected]


Issue Time Tracking
-------------------

    Worklog Id:     (was: 380616)
    Time Spent: 0.5h  (was: 20m)

> Token service should return a 401 or 403 response when the renewer is not 
> white-listed
> --------------------------------------------------------------------------------------
>
>                 Key: KNOX-2215
>                 URL: https://issues.apache.org/jira/browse/KNOX-2215
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>    Affects Versions: 1.4.0
>            Reporter: Philip Zampino
>            Assignee: Philip Zampino
>            Priority: Major
>          Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> Currently, when the Knox Token service receives a renewal or revocation 
> request from a user who is not white-listed, it responds with a HTTP 400 
> response. It should instead respond with a HTTP 401 or 403 to better reflect 
> the nature of the error.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to