[ https://issues.apache.org/jira/browse/HIVE-17606?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16187465#comment-16187465 ]
Tao Li commented on HIVE-17606: ------------------------------- Added a section here: https://cwiki.apache.org/confluence/display/Hive/HiveReplicationv2Development#HiveReplicationv2Development-MetastorenotificationAPIsecurity [~leftylev] Please let me know if you have any suggestions to improve it. Thanks! > Improve security for DB notification related APIs > ------------------------------------------------- > > Key: HIVE-17606 > URL: https://issues.apache.org/jira/browse/HIVE-17606 > Project: Hive > Issue Type: Improvement > Components: Metastore > Reporter: Tao Li > Assignee: Tao Li > Fix For: 3.0.0 > > Attachments: HIVE-17606.10.patch, HIVE-17606.1.patch, > HIVE-17606.2.patch, HIVE-17606.3.patch, HIVE-17606.4.patch, > HIVE-17606.5.patch, HIVE-17606.6.patch, HIVE-17606.7.patch, > HIVE-17606.8.patch, HIVE-17606.9.patch > > > The purpose is to make sure only the superusers which are specified in the > proxyuser settings can make the db notification related API calls, since this > is supposed to be called by superuser/admin instead of any end user. -- This message was sent by Atlassian JIRA (v6.4.14#64029)