You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@ignite.apache.org by "Ignite TC Bot (Jira)" <ji...@apache.org> on 2019/10/10 21:14:00 UTC
[jira] [Commented] (IGNITE-12220) Allow to use cache-related
permissions both at system and per-cache levels
[ https://issues.apache.org/jira/browse/IGNITE-12220?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16948947#comment-16948947 ]
Ignite TC Bot commented on IGNITE-12220:
----------------------------------------
{panel:title=Branch: [pull/6904/head] Base: [master] : No blockers found!|borderStyle=dashed|borderColor=#ccc|titleBGColor=#D6F7C1}{panel}
[TeamCity *--> Run :: All* Results|https://ci.ignite.apache.org/viewLog.html?buildId=4683308&buildTypeId=IgniteTests24Java8_RunAll]
> Allow to use cache-related permissions both at system and per-cache levels
> --------------------------------------------------------------------------
>
> Key: IGNITE-12220
> URL: https://issues.apache.org/jira/browse/IGNITE-12220
> Project: Ignite
> Issue Type: Task
> Components: security
> Affects Versions: 2.7.6
> Reporter: Andrey Kuznetsov
> Assignee: Sergei Ryzhov
> Priority: Major
> Fix For: 2.8
>
> Time Spent: 3.5h
> Remaining Estimate: 0h
>
> Currently, {{CACHE_CREATE}} and {{CACHE_DESTROY}} permissions are enforced to be system-level permissions, see for instance {{SecurityPermissionSetBuilder#appendCachePermissions}}. This looks inflexible: Ignite Security implementations are not able to manage cache creation and deletion permissions on per-cache basis (unlike get/put/remove permissions). All such limitations should be found and removed in order to allow all {{CACHE_*}} permissions to be set both at system and per-cache levels.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)