[ 
https://issues.apache.org/jira/browse/PHOENIX-5905?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17113759#comment-17113759
 ] 

Istvan Toth commented on PHOENIX-5905:
--------------------------------------

[~rajeshbabu] 

Your explanation and the code change doesn't seem to match.

The code change applies to the native HBase auth, while according to your 
explanation the problem is with the custom authenticators, which are not 
affected by this change.

(And which don't work at all anyway, as far as I understand (see my earlier 
FIXME comments))

> Reset user to hbase by changing rpc context before getting user permissions 
> on access controller service 
> ---------------------------------------------------------------------------------------------------------
>
>                 Key: PHOENIX-5905
>                 URL: https://issues.apache.org/jira/browse/PHOENIX-5905
>             Project: Phoenix
>          Issue Type: Bug
>            Reporter: Rajeshbabu Chintaguntla
>            Assignee: Rajeshbabu Chintaguntla
>            Priority: Major
>             Fix For: 5.1.0, 4.16.0
>
>         Attachments: PHOENIX-5905.patch
>
>
> Currently we are calling getUserPermissions with hbase user directly on 
> access controller service which is not a rpc call. If we don't reset user 
> system user will be considered and might expect extra privileges  to return 
> the user  permissions.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to