You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@kylin.apache.org by "jiatao.tao (JIRA)" <ji...@apache.org> on 2017/10/26 07:49:00 UTC

[jira] [Commented] (KYLIN-2960) We should submit a new feature that it support the authentication for user and role and the authentication for user and group when the LDAP authentication was enabled.

    [ https://issues.apache.org/jira/browse/KYLIN-2960?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16220117#comment-16220117 ] 

jiatao.tao commented on KYLIN-2960:
-----------------------------------

Hi jianhua, it seems can directly get user's authorities by calling Authentication#getAuthorities(). You can take a look at AuthoritiesPopulator.java, it needs some small change to achieve this.

> We should submit a new feature that it support the authentication for user and role and the authentication for user and group when the LDAP authentication was enabled.
> -----------------------------------------------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: KYLIN-2960
>                 URL: https://issues.apache.org/jira/browse/KYLIN-2960
>             Project: Kylin
>          Issue Type: New Feature
>          Components: General
>            Reporter: peng.jianhua
>            Assignee: peng.jianhua
>              Labels: patch
>         Attachments: 0001-KYLIN-2960-We-should-submit-a-new-feature-that-it-su.patch
>
>
> Currently, the user authentication interface that was provided by kylin to the third party only supports user and role authentication. However only user and group have authentication function when we use the LDAP authentication. In fact the authentication for user and role and the authentication for user and group have the same functional characteristics between different appplication system. So we should submit a new feature that it support the authentication for user and role and the authentication for user and group when the LDAP authentication was enabled.
> We supplied the checkPermission interface to implement the new feature. In the interface we set user groups information to the userRoles parameter when the LDAP was enabled, on the contrary we set user roles information to the userRoles parameter. The interface is as following:
> /**
>  * Checks if a user has permission on an entity.
>  * 
>  * @param user
>  * @param userRoles
>  * @param entityType String constants defined in AclEntityType 
>  * @param entityUuid
>  * @param permission
>  * 
>  * @return true if has permission
>  */
> abstract public boolean checkPermission(String user, List<String> userRoles, //
> 		String entityType, String entityUuid, Permission permission);



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)