Hello Zoltan Chovan, Alexey Serbin,

I'd like you to do a code review. Please visit

    http://gerrit.cloudera.org:8080/24826

to review the following change.


Change subject: [rpc] Add proxy user identity support
......................................................................

[rpc] Add proxy user identity support

Enable a client to act on behalf of another user (KUDU-3586), following
the semantics of Hadoop's SASL proxyuser protocol: for impersonation,
USER is the impersonated (effective) user and AUTHNAME is the real user.

Client side:

* UserCredentials gains an optional effective_user field that is empty
  by default and participates in HashCode()/operator==() so that
  connections with different effective users are never conflated.
  AuthenticationCredentialsPB gains a matching field so a proxied
  identity survives credential export and import (e.g. from a Spark
  driver to its executors).
* ClientNegotiation registers a SASL_CB_USER callback when an effective
  user is configured, sending it as the SASL authorization identity
  while still authenticating as the real user.

Server side:

* RemoteUser tracks both identities: real_username_ is established by
  the authentication mechanism (SASL_AUTHUSER) while username_ remains
  the effective user and defaults to the real one. All downstream
  authorization and ownership checks keep using username_, while logs
  and RPC diagnostics retain both identities for auditability.
* After SASL completes, the server reads both identities and fails the
  negotiation if the authentication identity is missing: falling back
  to the authorization identity would make a proxy request appear to be
  a direct login and bypass proxy authorization.
* The effective user carried in the (deprecated) ConnectionContextPB
  user info is cross-checked against the SASL authorization identity
  for proxy sessions, rejecting clients that claim a different user at
  the connection-context layer. For regular connections the field is
  ignored, as it was by older versions of Kudu.
* The messenger carries a ProxyUserAuthorizer and the negotiation
  authorizes a proxy request against the real user, the effective user,
  the authentication type, and the peer address. Connections whose
  authorization identity matches their authentication identity skip the
  checks entirely.

A client with an effective user configured also stops using cached
authentication tokens: tokens are bound to their original user and
cannot be used to impersonate another user.

Change-Id: I3f26169f14552d2566272a32525156cd30627aa3
---
M src/kudu/rpc/client_negotiation.cc
M src/kudu/rpc/client_negotiation.h
M src/kudu/rpc/messenger.cc
M src/kudu/rpc/messenger.h
M src/kudu/rpc/negotiation.cc
M src/kudu/rpc/remote_user.cc
M src/kudu/rpc/remote_user.h
M src/kudu/rpc/rpc_header.proto
M src/kudu/rpc/server_negotiation.cc
M src/kudu/rpc/server_negotiation.h
M src/kudu/rpc/user_credentials.cc
M src/kudu/rpc/user_credentials.h
12 files changed, 209 insertions(+), 24 deletions(-)



  git pull ssh://gerrit.cloudera.org:29418/kudu refs/changes/26/24826/1
--
To view, visit http://gerrit.cloudera.org:8080/24826
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I3f26169f14552d2566272a32525156cd30627aa3
Gerrit-Change-Number: 24826
Gerrit-PatchSet: 1
Gerrit-Owner: mintao <[email protected]>
Gerrit-Reviewer: Alexey Serbin <[email protected]>
Gerrit-Reviewer: Zoltan Chovan <[email protected]>

Reply via email to