[
https://issues.apache.org/jira/browse/DRILL-3467?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Krystal closed DRILL-3467.
--------------------------
Verified that without impersonation if the drillbit user does not have FS
access to the schema, the client will not see the schema from "show databases".
Verified that with impersonation, the logged in client user do not see the
schemas from "show databases" if the user does not have FS access to the
schemas.
Verified BI tools such as Drill Explorer and Tableau that if the logged in user
does not have FS access to the any schemas, these schemas are not being
displayed for use.
> Restrict 'show databases' based on underlying permissions.
> ----------------------------------------------------------
>
> Key: DRILL-3467
> URL: https://issues.apache.org/jira/browse/DRILL-3467
> Project: Apache Drill
> Issue Type: Improvement
> Components: Metadata
> Reporter: Andy Pernsteiner
> Assignee: Venki Korukanti
> Fix For: 1.2.0
>
> Attachments: DRILL-3467-1.patch
>
>
> Ideally, an administrator would have the ability to restrict the visibility
> of workspaces based on the FS permissions that underly those workspaces.
> Currently it appears we only honor this for 'show tables' , but not for 'show
> databases'.
> Without this functionality (or something that gives an equivalent result),
> users will be able to see any and all workspaces, including ones which
> administrators may wish to keep 'invisible'. Additionally, when having
> hundreds (or potentially thousands) of users, seeing all workspaces via 'show
> databases' is likely to make it difficult for end-users to know what they can
> and cannot access.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)