[ https://issues.apache.org/jira/browse/HBASE-13239?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14361616#comment-14361616 ]
Jerry He commented on HBASE-13239: ---------------------------------- Tested the cell ACL with groups. Works wonderfully. As 'user1' {code} hbase(main):014:0> scan 'table1' ROW COLUMN+CELL 0 row(s) in 0.3340 seconds {code} As 'admin' {code} hbase(main):032:0> grant 'table1', {'@users' => 'RW'}, {FILTER => "(PrefixFilter ('r'))"} 3 row(s) in 0.0240 seconds {code} As 'user1' {code} hbase(main):015:0> scan 'table1' ROW COLUMN+CELL r1 column=family:c1, timestamp=1426311391957, value=value1 r2 column=family:c1, timestamp=1426311399390, value=value2 r3 column=family:c1, timestamp=1426311405686, value=value3 3 row(s) in 0.0200 seconds {code} > Hbase grants at specific column level does not work for Groups > ---------------------------------------------------------------- > > Key: HBASE-13239 > URL: https://issues.apache.org/jira/browse/HBASE-13239 > Project: HBase > Issue Type: Bug > Components: hbase > Affects Versions: 0.98.4 > Reporter: Jaymin Patel > Assignee: Ted Yu > Fix For: 2.0.0, 1.0.1, 1.1.0, 0.98.12 > > Attachments: 13239-v1.txt, 13239-v2.txt > > > While performing Grant command to a specific column in a table - to a > specific group does not produce needed results. However, when specific user > is mentioned (instead of group name) in grant command, it becomes effective > Steps to Reproduce : > 1) using super-user, Grant a table/column family/column level grant to a group > 2) login using a user ( part of the above group) and scan the table. It does > not return any results > 3) using super-user, Grant a table/column family/column level grant to a > specific user ( instead of group) > 4) login using that specific user and scan the table. It produces correct > results, i.e. provides only the column where user has select privileges -- This message was sent by Atlassian JIRA (v6.3.4#6332)