apache / apache/kyuubi

[SECURITY] Check the user name for SessionsResource API

Open
#3,767 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Scala
Stars
2.4k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

### Code of Conduct

- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [X] I have searched in the [issues](https://github.com/apache/incubator-kyuubi/issues?q=is%3Aissue) and found no similar issues.

### What would you like to be improved?

Now there is no user name check for SessionsResource API, it is not security.

### How should we improve?

check the user name, it should be same with the session user.

### Are you willing to submit PR?

- [ ] Yes. I can submit a PR independently to improve.
- [ ] Yes. I would be willing to submit a PR with guidance from the Kyuubi community to improve.
- [ ] No. I cannot submit a PR at this time.

Contributor guide

Open the contributing guide

Research direction

Start by locating the SessionsResource API and reading how it obtains the session user and handles the request username. Confirm the expected behavior from the issue: the username must match the session user, and verify the change with the relevant existing or new API tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
scala
Domain
api, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.