<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Hue and Oozie security - users can access resources they shouldn't? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80139#M83651</link>
    <description>Regarding the 1st point, are you using Sentry? I am quite sure, that in correct configuration the HDFS is not browsable from Hue if the owner/group does not match.&lt;BR /&gt;Or.. maybe you have ACLs enabled on HDFS, and on this directory from the print screen there are more permissions. If you have acls enabled, then check it by hdfs dfs -getfacl &amp;lt;path&amp;gt;</description>
    <pubDate>Thu, 20 Sep 2018 19:10:10 GMT</pubDate>
    <dc:creator>Tomas79</dc:creator>
    <dc:date>2018-09-20T19:10:10Z</dc:date>
    <item>
      <title>Hue and Oozie security - users can access resources they shouldn't?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80025#M83650</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ask here for an advice on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;hue configuration.&lt;/P&gt;&lt;P&gt;We are developing a KDC security-enabled cluster with multiple users belonging to various groups.&lt;/P&gt;&lt;P&gt;Currently&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;we rely heavily on Hue and Oozie workflows that are designed from Hue.&lt;/P&gt;&lt;P&gt;Users create their&amp;nbsp;workflows under their user in Hue.&amp;nbsp;Workflows of a particular user are not accessible to others from the list of workflows, unless explicitly shared, which is fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However there are problems we'd like to solve:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;Other&amp;nbsp;users still can access workspaces of those workflows&amp;nbsp;via&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;HDFS, either with Hue's "File browser" or directly via&amp;nbsp;hdfs command. Particulary from Hue, seems that anyone can access workspace directory and even open its files, even if&amp;nbsp;I explicitly change the dir and files permission to 600. (See screenshot attached)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hue-permissions.png" style="width: 600px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/4832iCD3A4B7AC4E5B0D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="hue-permissions.png" alt="hue-permissions.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The properties of the launched workflows can be seen by&amp;nbsp;other users in the "Configuration" tab, regardless of their&amp;nbsp;permissions on the workflow. Can those values be hidden somehow?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hue-configuration-permissions.png" style="width: 600px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/4833iE473701B8DC3DC91/image-size/large?v=v2&amp;amp;px=999" role="button" title="hue-configuration-permissions.png" alt="hue-configuration-permissions.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:43:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80025#M83650</guid>
      <dc:creator>elkarel</dc:creator>
      <dc:date>2026-04-21T13:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Hue and Oozie security - users can access resources they shouldn't?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80139#M83651</link>
      <description>Regarding the 1st point, are you using Sentry? I am quite sure, that in correct configuration the HDFS is not browsable from Hue if the owner/group does not match.&lt;BR /&gt;Or.. maybe you have ACLs enabled on HDFS, and on this directory from the print screen there are more permissions. If you have acls enabled, then check it by hdfs dfs -getfacl &amp;lt;path&amp;gt;</description>
      <pubDate>Thu, 20 Sep 2018 19:10:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80139#M83651</guid>
      <dc:creator>Tomas79</dc:creator>
      <dc:date>2018-09-20T19:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Hue and Oozie security - users can access resources they shouldn't?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80379#M83652</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response. We are not using Sentry.&lt;/P&gt;&lt;P&gt;The output of getfacl is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;hdfs dfs -getfacl /user/hue/oozie/workspaces/hue-oozie-1538051691.26&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;# file: /user/hue/oozie/workspaces/hue-oozie-1538051691.26&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;# owner: SVC_CTOS_SENTILO&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;# group: hue&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;getfacl: The ACL operation has been rejected. Support for ACLs has been disabled by setting dfs.namenode.acls.enabled to false.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Incidently, I am even&amp;nbsp;able to edit the file that is at 0600, being owned&amp;nbsp;by another user.&lt;/P&gt;&lt;P&gt;I also created a 0600 folder and inside a 0600 file. Same behaviour.&lt;/P&gt;&lt;P&gt;Both users are in hadoop and hue group, but that shouldn't be a problem, since as far as I understand it, 0600 means only the owner of the file should be able to read an write, and nobody else.&lt;/P&gt;&lt;P&gt;The owner of the file is SVC_CTOS_SENTILO, from Hue as well from hdfs dfs CLI command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 13:11:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80379#M83652</guid>
      <dc:creator>elkarel</dc:creator>
      <dc:date>2018-09-27T13:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hue and Oozie security - users can access resources they shouldn't?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80411#M83653</link>
      <description>&lt;P&gt;All solved, it was a misconfiguration of HDFS.&lt;/P&gt;&lt;P&gt;The property&amp;nbsp;dfs.permissions was set to false (!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 07:17:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-and-Oozie-security-users-can-access-resources-they/m-p/80411#M83653</guid>
      <dc:creator>elkarel</dc:creator>
      <dc:date>2018-09-28T07:17:34Z</dc:date>
    </item>
  </channel>
</rss>

