-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Closed
Labels
area/enterpriseRelated to proprietary featuresRelated to proprietary featuresarea/securitySecurity related issuesSecurity related issueskind/enhancementSomething could be better.Something could be better.priority/P1Serious issue that requires eventual attention (can wait a bit)Serious issue that requires eventual attention (can wait a bit)status/acceptedWe accept to investigate/work on it.We accept to investigate/work on it.
Milestone
Description
Currently if dgraph cluster is booted up with ACL on, all predicates can be accessed until first rule is created. Ideally we should not allow access to any predicates by default if ACL is on. We can expose acl_allow_all flag to allow access to all predicates after the cluster boot up.
Final behaviour will look as follows -
ACL is off
Access to all predicates is OK
ACL is on
NO Access to any predicates for reading/writing/modifying
ACL is on but cluster is run with the option acl_allow_on
Access to all predicates is OK
Metadata
Metadata
Assignees
Labels
area/enterpriseRelated to proprietary featuresRelated to proprietary featuresarea/securitySecurity related issuesSecurity related issueskind/enhancementSomething could be better.Something could be better.priority/P1Serious issue that requires eventual attention (can wait a bit)Serious issue that requires eventual attention (can wait a bit)status/acceptedWe accept to investigate/work on it.We accept to investigate/work on it.