trafodion-codereview mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From robertamarton <...@git.apache.org>
Subject [GitHub] incubator-trafodion pull request #806: TRAFODION-2330 Using trafci, a select...
Date Tue, 01 Nov 2016 05:24:26 GMT
GitHub user robertamarton opened a pull request:

    https://github.com/apache/incubator-trafodion/pull/806

    TRAFODION-2330 Using trafci, a select from a table succeeds even if t…

    …he user
    
                   does not have the priv
    
    There is a problem when the session user changes in a mxosrvr process.  The
    existing compiler caches are not getting cleared so the new user will be
    accessing the previous users' caches.  This could lead to allowing someone
    that does not have privileges to gain access to an object.
    
    The change is to clear all caches during a session user change operation.

You can merge this pull request into a Git repository by running:

    $ git pull https://github.com/robertamarton/incubator-trafodion traf-2330

Alternatively you can review and apply these changes as the patch at:

    https://github.com/apache/incubator-trafodion/pull/806.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

    This closes #806
    
----
commit 6cd6be853fb1508e7b33d8e12c0fea0a0a8ef044
Author: Roberta Marton <rmarton@edev07.esgyn.local>
Date:   2016-11-01T05:22:44Z

    TRAFODION-2330 Using trafci, a select from a table succeeds even if the user
                   does not have the priv
    
    There is a problem when the session user changes in a mxosrvr process.  The
    existing compiler caches are not getting cleared so the new user will be
    accessing the previous users' caches.  This could lead to allowing someone
    that does not have privileges to gain access to an object.
    
    The change is to clear all caches during a session user change operation.

----


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at infrastructure@apache.org or file a JIRA ticket
with INFRA.
---

Mime
View raw message