[jira] [Created] (KYLIN-2646) Project level query authorization

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view

[jira] [Created] (KYLIN-2646) Project level query authorization

JIRA jira@apache.org
hongbin ma created KYLIN-2646:

             Summary: Project level query authorization
                 Key: KYLIN-2646
                 URL: https://issues.apache.org/jira/browse/KYLIN-2646
             Project: Kylin
          Issue Type: Improvement
            Reporter: hongbin ma
            Assignee: hongbin ma

As we introduced ad-hoc queries in https://issues.apache.org/jira/browse/KYLIN-2515, we'll need to adjust query authorization as follows:

 Query authorization is encouraged to be set as project level. If someone is assigned READ permission on project, then he has access to query all tables in the project, regardless thru adhoc or cubes

 If a user has READ permission on cubes but no READ permission on project. He can only issue queries only if the query can be satisfied by those cubes he has READ permission.

This message was sent by Atlassian JIRA