[ 
https://issues.apache.org/jira/browse/KNOX-3268?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sandor Molnar updated KNOX-3268:
--------------------------------

+Apache Knox 3.0.0 release preparation+
   
We are about to cut the 3.0.0 release branch. master will move on to 3.1.0.
This issue is currently unresolved and is not automatically included in 3.0.0. 
Please choose one of the following:
# If this belongs in 3.0.0: once the branch is cut, cherry-pick your commit(s) 
onto the new v3.0.0 branch in addition to master. Leave Fix Version = 3.0.0 so 
we can track it.
# Do nothing: we will move this issue to the next release (3.1.0) as part of 
release cleanup.
   
If we don't hear back and see no cherry-pick, the issue will be re-targeted to 
3.1.0. Thanks!

> Add {username} variable for Dynamic Path Based ACLs
> ---------------------------------------------------
>
>                 Key: KNOX-3268
>                 URL: https://issues.apache.org/jira/browse/KNOX-3268
>             Project: Apache Knox
>          Issue Type: Improvement
>          Components: Authorization
>            Reporter: Larry McCay
>            Assignee: Larry McCay
>            Priority: Major
>             Fix For: 3.0.0
>
>
> Let's extend the path based acls syntax to also support dynamic variable 
> within a path such as {username}. This would mean that the path could check 
> the authenticated user against a particular resource path being requested 
> within a regex expression.
> This could provide the ability to grant authenticated users to things like 
> user specific namespaces or home directories.
> KNOX-3267 could pave the way for user specific namespaces within credential 
> stores. In which case an API to retrieve their credentials within their 
> namespace could be provide and protected to grant access only to their own 
> namespace.
> We may also be able to extend the same for {group-in} for namespace access 
> granted to specific groups.
> This needs continued thought and discussion.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to