[Bug] Kyuubi submitted the GROUP as a USER to RANGER for authentication.
- Dominant language
- Scala
- Stars
- 2.4k
- Forks
- 1k
- PR merge metrics
- No merged PRs in 30d
Description
### Code of Conduct
- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)
### Search before asking
- [X] I have searched in the [issues](https://github.com/apache/incubator-kyuubi/issues?q=is%3Aissue) and found no similar issues.
### Describe the bug
Kyuubi-1.4 uses GROUP isolation and RANGER permission authentication.
Kyuubi submitted the GROUP as a USER to RANGER for authentication.
This requires the creation of corresponding users in RANGER system.
Only then can authority management be realized.
### Affects Version(s)
1.4.0
### Kyuubi Server Log Output
_No response_
### Kyuubi Engine Log Output
_No response_
### Kyuubi Server Configurations
_No response_
### Kyuubi Engine Configurations
_No response_
### Additional context
_No response_
### Are you willing to submit PR?
- [X] Yes I am willing to submit a PR!
Contributor guide
Research direction
The report names Kyuubi 1.4, GROUP isolation, and Ranger permission authentication, but no source files, tests, or entry points. Start by locating Kyuubi's Ranger integration and the code that maps GROUP identities before authentication; reproduce the configuration and verify that Ranger receives the intended identity without requiring a matching user.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- scala
- Domain
- authentication, authorization
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100