Skip to content

RANGER-5749: Limit concurrent Ranger Admin UI sessions per user - #1235

Open
eoinmcdonnell113 wants to merge 1 commit into
apache:ranger-2.10from
eoinmcdonnell113:RANGER-5749-ranger-2.10
Open

eoinmcdonnell113 wants to merge 1 commit into
apache:ranger-2.10from
eoinmcdonnell113:RANGER-5749-ranger-2.10

Conversation

@eoinmcdonnell113

Copy link
Copy Markdown
Contributor

Cherry-pick of 1641c7d (#1200) from master.

https://issues.apache.org/jira/browse/RANGER-5749

(cherry picked from commit 1641c7d)

What changes were proposed in this pull request?
RANGER-5749: Limit concurrent Ranger Admin UI sessions per user.

Adds ranger.session.limit.concurrency (default 0 = no limit). When the limit is exceeded, the oldest UI session for that user is expired so the new login succeeds. Plugin policy/tag/role download sessions do not count.

Form-login sessions are invalidated and sent to the Ranger login page. Knox SSO / Trusted Proxy sessions are marked expired and redirected to Knox login using the existing inactivity-timeout path.

JIRA: https://issues.apache.org/jira/browse/RANGER-5749

How was this patch tested?
Unit tests: TestSessionMgr, TestRangerHttpSessionListener, TestRangerKRBAuthenticationFilter (46 tests, 0 failures, 2 skipped).
Manual test on Ranger Admin Docker/UI with ranger.session.limit.concurrency=1: a second browser login as the same user expires the first session. The first browser is sent back to the Ranger login page.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants