[ 
https://issues.apache.org/jira/browse/MAPREDUCE-6741?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15388293#comment-15388293
 ] 

Jason Lowe commented on MAPREDUCE-6741:
---------------------------------------

bq. Anyone who has access to JHS web UI essentially has access to Job Conf of 
any other users' job.

This is not true.  The job's setting for mapreduce.job.acl-view-job is 
respected by the history server, and users who do not have view access will not 
be able to see the job's configuration even though they have access to the JHS 
web UI.

Having the ability to filter individual conf keys is one thing, but they should 
not be completely wide-open today unless the user didn't bother to restrict the 
visibility of their job.

> add JHS support to hide job conf properties from Web UI
> -------------------------------------------------------
>
>                 Key: MAPREDUCE-6741
>                 URL: https://issues.apache.org/jira/browse/MAPREDUCE-6741
>             Project: Hadoop Map/Reduce
>          Issue Type: Improvement
>          Components: mrv2
>    Affects Versions: 2.7.2
>            Reporter: Haibo Chen
>            Assignee: Haibo Chen
>
> JHS today display all Job conf properties in Web UI directly. Anyone who has 
> access to JHS web UI essentially has access to Job Conf of any other users' 
> job. Users may have some credentials or any sensitive information they added 
> to the job conf. It'd be nice if we can allow users to specify a set of 
> properties which JHS will filter out when Job conf is displayed.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: mapreduce-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: mapreduce-issues-h...@hadoop.apache.org

Reply via email to