You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ambari.apache.org by "Siddharth Wagle (JIRA)" <ji...@apache.org> on 2014/09/27 02:09:33 UTC

[jira] [Created] (AMBARI-7530) Admin: /users and /groups resources should only be accessible from AMBARI.ADMIN

Siddharth Wagle created AMBARI-7530:
---------------------------------------

             Summary: Admin: /users and /groups resources should only be accessible from AMBARI.ADMIN
                 Key: AMBARI-7530
                 URL: https://issues.apache.org/jira/browse/AMBARI-7530
             Project: Ambari
          Issue Type: Bug
          Components: ambari-admin
    Affects Versions: 1.7.0
            Reporter: Siddharth Wagle
            Assignee: Siddharth Wagle
             Fix For: 1.7.0


[~tbeerbower] what we discussed. A non AMBARI.ADMIN should not be able to GET on the following resources:

/api/v1/users
/api/v1/groups




--
This message was sent by Atlassian JIRA
(v6.3.4#6332)