[
https://issues.apache.org/jira/browse/RANGER-5729?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Sanket Shelar resolved RANGER-5729.
-----------------------------------
Resolution: Fixed
> Unable to import exported GDS policies via Service Manager due to 403 Error
> ---------------------------------------------------------------------------
>
> Key: RANGER-5729
> URL: https://issues.apache.org/jira/browse/RANGER-5729
> Project: Ranger
> Issue Type: Bug
> Components: Ranger
> Reporter: Sanket Shelar
> Assignee: Sanket Shelar
> Priority: Minor
> Fix For: 3.0.0
>
> Time Spent: 40m
> Remaining Estimate: 0h
>
> If a GDS-related policy is present on the cluster and we export policies from
> the Report page, it exports *all* policies. However, when trying to import
> that policy via the Service Manager page, it triggers a 403 error
> h3. Steps to Reproduce
> # Ensure a GDS-related policy is present on the cluster.
> # Navigate to the *Report* page and export the policy.
> # Navigate to the *Service Manager* page.
> # Attempt to import the newly exported policy file.
>
> {code:java}
> beeline -e "create database vehicle;"
> beeline -e "create table vehicle.cars(car_id int, car_name string, car_color
> string, car_price int);"
> beeline -e "select * from vehicle.cars;"
> ------------------Create datashare---------
> curl -ik -u admin:rangerR0cks! -X POST -H 'Content-type:application/json'
> 'http://localhost:6080/service/gds/datashare' -d '{"name": "test_qyhusmk",
> "service": "dev_hive", "description": "test description 1", "acl": {"users":
> {"hive": "LIST"}, "groups": {}, "roles": {}}, "zone": "",
> "defaultAccessTypes": ["all"], "defaultTagMasks": [], "conditionExpr": null,
> "termsOfUse": "Test terms and conditions"}'
> -------------------create resource in the datashare---------
> curl -ik -u admin:rangerR0cks! -X POST -H 'Content-type:application/json'
> 'http://localhost:6080/service/gds/resource' -d '{"name":
> "test_resource_test_qyhusmk", "dataShareId": 1, "resource": {"column":
> {"values": ["*"], "isExcludes": false, "isRecursive": false}, "table":
> {"values": ["cars"], "isExcludes": false, "isRecursive": false}, "database":
> {"values": ["vehicle"], "isExcludes": false, "isRecursive": false}},
> "conditionExpr": null, "accessTypes": null}'
> -----------------------Create dataset--------------
> curl -ik -u admin:rangerR0cks! -X POST -H 'Content-type:application/json'
> 'http://localhost:6080/service/gds/dataset' -d '{"name": "dataset_test1",
> "acl": {"users": {"admin": "ADMIN"}, "groups": {}, "roles": {}},
> "description": "dataset_qyhusmk_description", "termsOfUse": ""}'
> --------------------Create dataset policy-------
> curl -ik -u admin:rangerR0cks! -X POST -H 'Content-type:application/json'
> 'http://localhost:6080/service/gds/dataset/1/policy' -d
> '{"policyItems":[{"accesses":[{"type":"_READ","isAllowed":true}],"users":["hive"],"groups":[],"roles":[]}],"policyLabels":[],"policyPriority":"0","resources":{"dataset":{"values":["dataset_test1"]}},"conditions":[]}'
> ----------------------Add datashare in the dataset-------
> curl -ik -u admin:rangerR0cks! -X POST -H 'Content-type:application/json'
> 'http://localhost:6080/service/gds/datashare/dataset' -d '{"datasetId": 1,
> "dataShareId": 1, "status": "ACTIVE"}'
> {code}
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)