apache / apache/kyuubi

[Bug] Kyuubi submitted the GROUP as a USER to RANGER for authentication.

Open
#1,627 12 comments 0 reactions 0 assignees View on GitHub
Dominant language
Scala
Stars
2.4k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

### Code of Conduct

- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [X] I have searched in the [issues](https://github.com/apache/incubator-kyuubi/issues?q=is%3Aissue) and found no similar issues.

### Describe the bug

Kyuubi-1.4 uses GROUP isolation and RANGER permission authentication.
Kyuubi submitted the GROUP as a USER to RANGER for authentication.
This requires the creation of corresponding users in RANGER system.
Only then can authority management be realized.

### Affects Version(s)

1.4.0

### Kyuubi Server Log Output

_No response_

### Kyuubi Engine Log Output

_No response_

### Kyuubi Server Configurations

_No response_

### Kyuubi Engine Configurations

_No response_

### Additional context

_No response_

### Are you willing to submit PR?

- [X] Yes I am willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

The report names Kyuubi 1.4, GROUP isolation, and Ranger permission authentication, but no source files, tests, or entry points. Start by locating Kyuubi's Ranger integration and the code that maps GROUP identities before authentication; reproduce the configuration and verify that Ranger receives the intended identity without requiring a matching user.

Written by the indexing model from the issue text.

Assessment

Tech stack
scala
Domain
authentication, authorization
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.