Todd Lipcon has posted comments on this change. ( http://gerrit.cloudera.org:8080/11331 )
Change subject: Add missing authorization in KRPC ...................................................................... Patch Set 5: (2 comments) http://gerrit.cloudera.org:8080/#/c/11331/5/be/src/rpc/authentication.cc File be/src/rpc/authentication.cc: http://gerrit.cloudera.org:8080/#/c/11331/5/be/src/rpc/authentication.cc@734 PS5, Line 734: return Status(Substitute("FLAGS_krb5_ccname '$0' is not an absolute file path", nit: use the user-facing name --krb5_ccname instead of FLAGS_... which is internal-only http://gerrit.cloudera.org:8080/#/c/11331/5/be/src/rpc/rpc-mgr.cc File be/src/rpc/rpc-mgr.cc: http://gerrit.cloudera.org:8080/#/c/11331/5/be/src/rpc/rpc-mgr.cc@172 PS5, Line 172: LOG(ERROR) << Substitute("Unauthorized access from $0. Expected user: $1", sorry, think I wasn't entirely clear. I think the error message should still also include the service. Maybe it should also be slightly more clear to say "rejecting unauthorized access" or something, since a user might be scared into thinking "uh oh! there was unauthorized access!" -- To view, visit http://gerrit.cloudera.org:8080/11331 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I2f82dee5e721f2ed23e75fd91abbc6ab7addd4c5 Gerrit-Change-Number: 11331 Gerrit-PatchSet: 5 Gerrit-Owner: Michael Ho <k...@cloudera.com> Gerrit-Reviewer: Impala Public Jenkins <impala-public-jenk...@cloudera.com> Gerrit-Reviewer: Michael Ho <k...@cloudera.com> Gerrit-Reviewer: Sailesh Mukil <sail...@cloudera.com> Gerrit-Reviewer: Todd Lipcon <t...@apache.org> Gerrit-Comment-Date: Wed, 29 Aug 2018 08:29:59 +0000 Gerrit-HasComments: Yes