Skip to content

[Console] Add missing RBAC on SettingController get and checkHadoop#4393

Closed
shangeyao wants to merge 1 commit into
apache:devfrom
shangeyao:fix/setting-controller-rbac
Closed

[Console] Add missing RBAC on SettingController get and checkHadoop#4393
shangeyao wants to merge 1 commit into
apache:devfrom
shangeyao:fix/setting-controller-rbac

Conversation

@shangeyao

Copy link
Copy Markdown
Contributor

Summary

  • Add @RequiresPermissions("setting:view") to SettingController.get
  • Add @RequiresPermissions("setting:view") to SettingController.checkHadoop

Fixes #4392

Test plan

  • User without setting:view cannot call /setting/get
  • User without setting:view cannot call /setting/check/hadoop

AI Disclosure

  • Model: Claude Opus 4.6
  • Platform/Tool: Cursor
  • Human Oversight: partially reviewed
  • Prompt Summary: Close SettingController RBAC gap from dev branch scan

Made with Cursor

Require setting:view permission for single-key reads and Hadoop checks.

Generated-by: Cursor
Co-authored-by: Cursor <cursoragent@cursor.com>
@shangeyao

Copy link
Copy Markdown
Contributor Author

Closing this PR because the StreamPark Console frontend is about to undergo a major refactor. These console-side changes would likely conflict with or require rework after the refactor. Will revisit relevant improvements once the new frontend architecture is in place.

@shangeyao shangeyao closed this Jun 30, 2026
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Console] Add missing RBAC on SettingController get and checkHadoop

1 participant