Skip to content

RANGER-5749: Limit concurrent Ranger Admin UI sessions per user - #1200

Open
eoinmcdonnell113 wants to merge 1 commit into
apache:masterfrom
eoinmcdonnell113:RANGER-5749
Open

RANGER-5749: Limit concurrent Ranger Admin UI sessions per user#1200
eoinmcdonnell113 wants to merge 1 commit into
apache:masterfrom
eoinmcdonnell113:RANGER-5749

Conversation

@eoinmcdonnell113

Copy link
Copy Markdown
Contributor

Expire the oldest UI session when ranger.session.limit.concurrency is exceeded so a new login succeeds. Default 0 means unlimited.

What changes were proposed in this pull request?

RANGER-5749: Limit concurrent Ranger Admin UI sessions per user.

Adds ranger.session.limit.concurrency (default 0 = no limit). When the limit is exceeded, the oldest UI session for that user is expired so the new login succeeds. Plugin policy/tag/role download sessions do not count.

Form-login sessions are invalidated and sent to the Ranger login page. Knox SSO / Trusted Proxy sessions are marked expired and redirected to Knox login using the existing inactivity-timeout path.

JIRA: https://issues.apache.org/jira/browse/RANGER-5749

How was this patch tested?

Unit tests: TestSessionMgr, TestRangerHttpSessionListener, TestRangerKRBAuthenticationFilter (46 tests, 0 failures, 2 skipped).
Manual test on Ranger Admin Docker/UI with ranger.session.limit.concurrency=1: a second browser login as the same user expires the first session. The first browser is sent back to the Ranger login page.

Expire the oldest UI session when ranger.session.limit.concurrency is exceeded so a new login succeeds. Default 0 means unlimited.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants