Skip to content

RANGER-5539: Add Authorisation Check for doAsUser Parameter#915

Open
ChinmayHegde24 wants to merge 1 commit intoapache:masterfrom
ChinmayHegde24:RANGER-5539
Open

RANGER-5539: Add Authorisation Check for doAsUser Parameter#915
ChinmayHegde24 wants to merge 1 commit intoapache:masterfrom
ChinmayHegde24:RANGER-5539

Conversation

@ChinmayHegde24
Copy link
Copy Markdown
Contributor

Currently RangerJwtAuthHandler accepts the doAsUser value directly from the incoming request and uses it to establish the authenticated user identity without performing any validation.
So the user should be validated for impersonation permission on doAsUser parameter.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant