From f31d7f7eb211e49e25400e5839bb6738a91f7975 Mon Sep 17 00:00:00 2001 From: mbertozzi Date: Thu, 10 Jan 2013 00:34:32 +0000 Subject: [PATCH] HBASE-7526 create table does not log the table name in audit log git-svn-id: https://svn.apache.org/repos/asf/hbase/trunk@1431162 13f79535-47bb-0310-9956-ffa450edef68 --- .../hbase/security/access/AccessController.java | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/hbase-server/src/main/java/org/apache/hadoop/hbase/security/access/AccessController.java b/hbase-server/src/main/java/org/apache/hadoop/hbase/security/access/AccessController.java index 2ea58180f99..d39c7df1809 100644 --- a/hbase-server/src/main/java/org/apache/hadoop/hbase/security/access/AccessController.java +++ b/hbase-server/src/main/java/org/apache/hadoop/hbase/security/access/AccessController.java @@ -347,15 +347,7 @@ public class AccessController extends BaseRegionObserver * @throws AccessDeniedException if authorization is denied */ private void requirePermission(String request, Permission.Action perm) throws IOException { - User user = getActiveUser(); - if (authManager.authorize(user, perm)) { - logResult(AuthResult.allow(request, "Global check allowed", user, perm, null, null)); - } else { - logResult(AuthResult.deny(request, "Global check failed", user, perm, null, null)); - throw new AccessDeniedException("Insufficient permissions for user '" + - (user != null ? user.getShortName() : "null") +"' (global, action=" + - perm.toString() + ")"); - } + requireGlobalPermission(request, perm, null, null); } /** @@ -482,7 +474,12 @@ public class AccessController extends BaseRegionObserver @Override public void preCreateTable(ObserverContext c, HTableDescriptor desc, HRegionInfo[] regions) throws IOException { - requirePermission("createTable", Permission.Action.CREATE); + Set families = desc.getFamiliesKeys(); + HashMap> familyMap = Maps.newHashMapWithExpectedSize(families.size()); + for (byte[] family: families) { + familyMap.put(family, null); + } + requireGlobalPermission("createTable", Permission.Action.CREATE, desc.getName(), familyMap); } @Override