@Override public List<String> getCurrentRoleNames() throws HiveAuthzPluginException { List<String> roleNames = new ArrayList<String>(); for(HiveRoleGrant role : getCurrentRoles()){ roleNames.add(role.getRoleName()); } return roleNames; }
/** * @return true only if current role of user is Admin * @throws HiveAuthzPluginException */ boolean isUserAdmin() throws HiveAuthzPluginException { List<HiveRoleGrant> roles; roles = getCurrentRoles(); for (HiveRoleGrant role : roles) { if (role.getRoleName().equalsIgnoreCase(HiveMetaStore.ADMIN)) { return true; } } return false; }
/** * @param roleName * @return true if roleName is the name of one of the roles (including the role hierarchy) * that the user belongs to. * @throws HiveAuthzPluginException */ private boolean userBelongsToRole(String roleName) throws HiveAuthzPluginException { for (HiveRoleGrant role : getRolesFromMS()) { // set to one of the roles user belongs to. if (role.getRoleName().equalsIgnoreCase(roleName)) { return true; } } return false; }
@Override public List<String> getCurrentRoleNames() throws HiveAuthzPluginException { List<String> roleNames = new ArrayList<String>(); for(HiveRoleGrant role : getCurrentRoles()){ roleNames.add(role.getRoleName()); } return roleNames; }
/** * @param roleName * @return true if roleName is the name of one of the roles (including the role hierarchy) * that the user belongs to. * @throws HiveAuthzPluginException */ private boolean userBelongsToRole(String roleName) throws HiveAuthzPluginException { for (HiveRoleGrant role : getRolesFromMS()) { // set to one of the roles user belongs to. if (role.getRoleName().equalsIgnoreCase(roleName)) { return true; } } return false; }
/** * @return true only if current role of user is Admin * @throws HiveAuthzPluginException */ boolean isUserAdmin() throws HiveAuthzPluginException { List<HiveRoleGrant> roles; roles = getCurrentRoles(); for (HiveRoleGrant role : roles) { if (role.getRoleName().equalsIgnoreCase(HiveMetaStore.ADMIN)) { return true; } } return false; }
private List<HiveRoleGrant> getRolesFromMS() throws HiveAuthzPluginException { try { List<RolePrincipalGrant> roles = getRoleGrants(currentUserName, PrincipalType.USER); Map<String, HiveRoleGrant> name2Rolesmap = new HashMap<String, HiveRoleGrant>(); getAllRoleAncestors(name2Rolesmap, roles); List<HiveRoleGrant> currentRoles = new ArrayList<HiveRoleGrant>(roles.size()); for (HiveRoleGrant role : name2Rolesmap.values()) { if (!HiveMetaStore.ADMIN.equalsIgnoreCase(role.getRoleName())) { currentRoles.add(role); } else { this.adminRole = role; } } return currentRoles; } catch (Exception e) { throw SQLAuthorizationUtils.getPluginException("Failed to retrieve roles for " + currentUserName, e); } }
private boolean doesUserHasAdminOption(List<String> roleNames) throws HiveAuthzPluginException { List<HiveRoleGrant> currentRoles; currentRoles = getCurrentRoles(); for (String roleName : roleNames) { boolean roleFound = false; for (HiveRoleGrant currentRole : currentRoles) { if (roleName.equalsIgnoreCase(currentRole.getRoleName())) { roleFound = true; if (!currentRole.isGrantOption()) { return false; } else { break; } } } if (!roleFound) { return false; } } return true; }
private List<HiveRoleGrant> getRolesFromMS() throws HiveAuthzPluginException { try { List<RolePrincipalGrant> roles = getRoleGrants(currentUserName, PrincipalType.USER); Map<String, HiveRoleGrant> name2Rolesmap = new HashMap<String, HiveRoleGrant>(); getAllRoleAncestors(name2Rolesmap, roles); List<HiveRoleGrant> currentRoles = new ArrayList<HiveRoleGrant>(roles.size()); for (HiveRoleGrant role : name2Rolesmap.values()) { if (!HiveMetaStore.ADMIN.equalsIgnoreCase(role.getRoleName())) { currentRoles.add(role); } else { this.adminRole = role; } } return currentRoles; } catch (Exception e) { throw SQLAuthorizationUtils.getPluginException("Failed to retrieve roles for " + currentUserName, e); } }
if (role.getRoleName().equalsIgnoreCase(roleName)) { currentRoles.clear(); currentRoles.add(role);
if (role.getRoleName().equalsIgnoreCase(roleName)) { currentRoles.clear(); currentRoles.add(role);
private boolean doesUserHasAdminOption(List<String> roleNames) throws HiveAuthzPluginException { List<HiveRoleGrant> currentRoles; currentRoles = getCurrentRoles(); for (String roleName : roleNames) { boolean roleFound = false; for (HiveRoleGrant currentRole : currentRoles) { if (roleName.equalsIgnoreCase(currentRole.getRoleName())) { roleFound = true; if (!currentRole.isGrantOption()) { return false; } else { break; } } } if (!roleFound) { return false; } } return true; }
static String writeRolesGrantedInfo(List<HiveRoleGrant> roles, boolean testMode) { if (roles == null || roles.isEmpty()) { return ""; } StringBuilder builder = new StringBuilder(); //sort the list to get sorted (deterministic) output (for ease of testing) Collections.sort(roles); for (HiveRoleGrant role : roles) { appendNonNull(builder, role.getRoleName(), true); appendNonNull(builder, role.isGrantOption()); appendNonNull(builder, testMode ? -1 : role.getGrantTime() * 1000L); appendNonNull(builder, role.getGrantor()); } return builder.toString(); }
static String writeRolesGrantedInfo(List<HiveRoleGrant> roles, boolean testMode) { if (roles == null || roles.isEmpty()) { return ""; } StringBuilder builder = new StringBuilder(); //sort the list to get sorted (deterministic) output (for ease of testing) Collections.sort(roles); for (HiveRoleGrant role : roles) { appendNonNull(builder, role.getRoleName(), true); appendNonNull(builder, role.isGrantOption()); appendNonNull(builder, testMode ? -1 : role.getGrantTime() * 1000L); appendNonNull(builder, role.getGrantor()); } return builder.toString(); }
@Override public List<String> getCurrentRoleNames() throws HiveAuthzPluginException { List<String> roleNames = new ArrayList<String>(); for(HiveRoleGrant role : getCurrentRoles()){ roleNames.add(role.getRoleName()); } return roleNames; }
/** * @return true only if current role of user is Admin * @throws HiveAuthzPluginException */ boolean isUserAdmin() throws HiveAuthzPluginException { List<HiveRoleGrant> roles; roles = getCurrentRoles(); for (HiveRoleGrant role : roles) { if (role.getRoleName().equalsIgnoreCase(HiveMetaStore.ADMIN)) { return true; } } return false; }
/** * @param roleName * @return true if roleName is the name of one of the roles (including the role hierarchy) * that the user belongs to. * @throws HiveAuthzPluginException */ private boolean userBelongsToRole(String roleName) throws HiveAuthzPluginException { for (HiveRoleGrant role : getRolesFromMS()) { // set to one of the roles user belongs to. if (role.getRoleName().equalsIgnoreCase(roleName)) { return true; } } return false; }
private List<HiveRoleGrant> getRolesFromMS() throws HiveAuthzPluginException { try { List<RolePrincipalGrant> roles = getRoleGrants(currentUserName, PrincipalType.USER); Map<String, HiveRoleGrant> name2Rolesmap = new HashMap<String, HiveRoleGrant>(); getAllRoleAncestors(name2Rolesmap, roles); List<HiveRoleGrant> currentRoles = new ArrayList<HiveRoleGrant>(roles.size()); for (HiveRoleGrant role : name2Rolesmap.values()) { if (!HiveMetaStore.ADMIN.equalsIgnoreCase(role.getRoleName())) { currentRoles.add(role); } else { this.adminRole = role; } } return currentRoles; } catch (Exception e) { throw SQLAuthorizationUtils.getPluginException("Failed to retrieve roles for " + currentUserName, e); } }
private boolean doesUserHasAdminOption(List<String> roleNames) throws HiveAuthzPluginException { List<HiveRoleGrant> currentRoles; currentRoles = getCurrentRoles(); for (String roleName : roleNames) { boolean roleFound = false; for (HiveRoleGrant currentRole : currentRoles) { if (roleName.equalsIgnoreCase(currentRole.getRoleName())) { roleFound = true; if (!currentRole.isGrantOption()) { return false; } else { break; } } } if (!roleFound) { return false; } } return true; }
static String writeRolesGrantedInfo(List<HiveRoleGrant> roles, boolean testMode) { if (roles == null || roles.isEmpty()) { return ""; } StringBuilder builder = new StringBuilder(); //sort the list to get sorted (deterministic) output (for ease of testing) Collections.sort(roles); for (HiveRoleGrant role : roles) { appendNonNull(builder, role.getRoleName(), true); appendNonNull(builder, role.isGrantOption()); appendNonNull(builder, testMode ? -1 : role.getGrantTime() * 1000L); appendNonNull(builder, role.getGrantor()); } return builder.toString(); }