You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@hive.apache.org by "Aihua Xu (JIRA)" <ji...@apache.org> on 2016/09/27 17:38:20 UTC

[jira] [Commented] (HIVE-14099) Hive security authorization can be disabled by users

    [ https://issues.apache.org/jira/browse/HIVE-14099?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15526874#comment-15526874 ] 

Aihua Xu commented on HIVE-14099:
---------------------------------

Of course, the admin can configure hive.conf.restricted.list even without this patch. But seems it's reasonable to add them as default ones.

> Hive security authorization can be disabled by users
> ----------------------------------------------------
>
>                 Key: HIVE-14099
>                 URL: https://issues.apache.org/jira/browse/HIVE-14099
>             Project: Hive
>          Issue Type: Improvement
>          Components: Authorization
>    Affects Versions: 0.13.1
>            Reporter: Prashant Kumar Singh
>            Assignee: Aihua Xu
>         Attachments: HIVE-14099.1.patch
>
>
> In case we enables :
> hive.security.authorization.enabled=true in hive-site.xml
> this setting can be disabled by users at their hive prompt. There should be hardcoded setting in the configs.
> The other thing is once we enable authorization, the tables that got created before enabling looses access as they don't have authorization defined. How this situation can be tackled in hive.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)