Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,6 @@
import io.druid.query.dimension.DimensionSpec;
import io.druid.query.groupby.GroupByQuery;
import io.druid.segment.QueryableIndex;
import io.druid.server.security.AuthConfig;
import io.druid.server.security.AuthTestUtils;
import io.druid.server.security.NoopEscalator;
import io.druid.sql.calcite.planner.DruidPlanner;
Expand Down Expand Up @@ -118,9 +117,7 @@ public void setup() throws Exception
CalciteTests.createOperatorTable(),
CalciteTests.createExprMacroTable(),
plannerConfig,
new AuthConfig(),
AuthTestUtils.TEST_AUTHORIZER_MAPPER,
new NoopEscalator(),
CalciteTests.getJsonMapper()
);
groupByQuery = GroupByQuery
Expand Down Expand Up @@ -182,7 +179,10 @@ public void queryNative(Blackhole blackhole) throws Exception
public void queryPlanner(Blackhole blackhole) throws Exception
{
try (final DruidPlanner planner = plannerFactory.createPlanner(null)) {
final PlannerResult plannerResult = planner.plan(sqlQuery);
final PlannerResult plannerResult = planner.plan(
sqlQuery,
NoopEscalator.getInstance().createEscalatedAuthenticationResult()
);
final List<Object[]> results = plannerResult.run().toList();
blackhole.consume(results);
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,6 @@
import io.druid.segment.incremental.IncrementalIndexSchema;
import io.druid.segment.virtual.ExpressionVirtualColumn;
import io.druid.segment.writeout.OffHeapMemorySegmentWriteOutMediumFactory;
import io.druid.server.security.AuthConfig;
import io.druid.server.security.AuthTestUtils;
import io.druid.server.security.NoopEscalator;
import io.druid.sql.calcite.filtration.Filtration;
Expand Down Expand Up @@ -137,9 +136,7 @@ public void setUp() throws Exception
operatorTable,
CalciteTests.createExprMacroTable(),
plannerConfig,
new AuthConfig(),
AuthTestUtils.TEST_AUTHORIZER_MAPPER,
new NoopEscalator(),
CalciteTests.getJsonMapper()
);
}
Expand Down Expand Up @@ -167,7 +164,10 @@ public void testQuantileOnFloatAndLongs() throws Exception
+ "APPROX_QUANTILE(cnt, 0.5)\n"
+ "FROM foo";

final PlannerResult plannerResult = planner.plan(sql);
final PlannerResult plannerResult = planner.plan(
sql,
NoopEscalator.getInstance().createEscalatedAuthenticationResult()
);

// Verify results
final List<Object[]> results = plannerResult.run().toList();
Expand Down Expand Up @@ -249,7 +249,10 @@ public void testQuantileOnComplexColumn() throws Exception
+ "APPROX_QUANTILE(hist_m1, 0.999) FILTER(WHERE dim1 = 'abc')\n"
+ "FROM foo";

final PlannerResult plannerResult = planner.plan(sql);
final PlannerResult plannerResult = planner.plan(
sql,
NoopEscalator.getInstance().createEscalatedAuthenticationResult()
);

// Verify results
final List<Object[]> results = plannerResult.run().toList();
Expand Down Expand Up @@ -302,7 +305,10 @@ public void testQuantileOnInnerQuery() throws Exception
final String sql = "SELECT AVG(x), APPROX_QUANTILE(x, 0.98)\n"
+ "FROM (SELECT dim2, SUM(m1) AS x FROM foo GROUP BY dim2)";

final PlannerResult plannerResult = planner.plan(sql);
final PlannerResult plannerResult = planner.plan(
sql,
NoopEscalator.getInstance().createEscalatedAuthenticationResult()
);

// Verify results
final List<Object[]> results = plannerResult.run().toList();
Expand Down
28 changes: 28 additions & 0 deletions server/src/main/java/io/druid/server/security/NoopEscalator.java
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,19 @@

package io.druid.server.security;

import com.fasterxml.jackson.annotation.JsonCreator;
import io.druid.java.util.http.client.HttpClient;

public class NoopEscalator implements Escalator
{
private static final NoopEscalator INSTANCE = new NoopEscalator();

@JsonCreator
public static NoopEscalator getInstance()
{
return INSTANCE;
}

@Override
public HttpClient createEscalatedClient(HttpClient baseClient)
{
Expand All @@ -34,4 +43,23 @@ public AuthenticationResult createEscalatedAuthenticationResult()
{
return AllowAllAuthenticator.ALLOW_ALL_RESULT;
}

@Override
public boolean equals(final Object obj)
{
//noinspection ObjectEquality
return obj.getClass() == getClass();
}

@Override
public int hashCode()
{
return 0;
}

@Override
public String toString()
{
return "NoopEscalator{}";
}
}
41 changes: 41 additions & 0 deletions server/src/test/java/io/druid/server/security/EscalatorTest.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
/*
* Licensed to Metamarkets Group Inc. (Metamarkets) under one
* or more contributor license agreements. See the NOTICE file
* distributed with this work for additional information
* regarding copyright ownership. Metamarkets licenses this file
* to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance
* with the License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing,
* software distributed under the License is distributed on an
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
* KIND, either express or implied. See the License for the
* specific language governing permissions and limitations
* under the License.
*/

package io.druid.server.security;

import com.fasterxml.jackson.databind.ObjectMapper;
import io.druid.segment.TestHelper;
import org.junit.Assert;
import org.junit.Test;

public class EscalatorTest
{
@Test
public void testSerde() throws Exception
{
final ObjectMapper objectMapper = TestHelper.makeJsonMapper();
Assert.assertEquals(
NoopEscalator.getInstance(),
objectMapper.readValue(
objectMapper.writeValueAsString(NoopEscalator.getInstance()),
Escalator.class
)
);
}
}
7 changes: 2 additions & 5 deletions sql/src/main/java/io/druid/sql/avatica/DruidMeta.java
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,6 @@
import io.druid.java.util.common.ISE;
import io.druid.java.util.common.StringUtils;
import io.druid.java.util.common.logger.Logger;
import io.druid.server.security.AuthConfig;
import io.druid.server.security.AuthenticationResult;
import io.druid.server.security.Authenticator;
import io.druid.server.security.AuthenticatorMapper;
Expand Down Expand Up @@ -67,7 +66,6 @@ public class DruidMeta extends MetaImpl
private final PlannerFactory plannerFactory;
private final ScheduledExecutorService exec;
private final AvaticaServerConfig config;
private final AuthConfig authConfig;
private final List<Authenticator> authenticators;

// Used to track logical connections.
Expand All @@ -81,14 +79,12 @@ public class DruidMeta extends MetaImpl
public DruidMeta(
final PlannerFactory plannerFactory,
final AvaticaServerConfig config,
final AuthConfig authConfig,
final Injector injector
)
{
super(null);
this.plannerFactory = Preconditions.checkNotNull(plannerFactory, "plannerFactory");
this.config = config;
this.authConfig = authConfig;
this.exec = Executors.newSingleThreadScheduledExecutor(
new ThreadFactoryBuilder()
.setNameFormat(StringUtils.format("DruidMeta@%s-ScheduledExecutor", Integer.toHexString(hashCode())))
Expand Down Expand Up @@ -183,7 +179,8 @@ public ExecuteResult prepareAndExecute(
if (authenticationResult == null) {
throw new ForbiddenException("Authentication failed.");
}
final Signature signature = druidStatement.prepare(plannerFactory, sql, maxRowCount, authenticationResult).getSignature();
final Signature signature = druidStatement.prepare(plannerFactory, sql, maxRowCount, authenticationResult)
.getSignature();
final Frame firstFrame = druidStatement.execute()
.nextFrame(
DruidStatement.START_OFFSET,
Expand Down
2 changes: 1 addition & 1 deletion sql/src/main/java/io/druid/sql/avatica/DruidStatement.java
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,7 @@ public DruidStatement prepare(
try (final DruidPlanner planner = plannerFactory.createPlanner(queryContext)) {
synchronized (lock) {
ensure(State.NEW);
this.plannerResult = planner.plan(query, null, authenticationResult);
this.plannerResult = planner.plan(query, authenticationResult);
this.maxRowCount = maxRowCount;
this.query = query;
this.signature = Meta.Signature.create(
Expand Down
37 changes: 25 additions & 12 deletions sql/src/main/java/io/druid/sql/calcite/planner/DruidPlanner.java
Original file line number Diff line number Diff line change
Expand Up @@ -20,19 +20,20 @@
package io.druid.sql.calcite.planner;

import com.google.common.base.Function;
import com.google.common.base.Preconditions;
import com.google.common.base.Supplier;
import com.google.common.base.Suppliers;
import com.google.common.collect.ImmutableList;
import com.google.common.collect.Iterables;
import com.google.common.collect.Sets;
import io.druid.java.util.common.ISE;
import io.druid.java.util.common.guava.Sequence;
import io.druid.java.util.common.guava.Sequences;
import io.druid.server.security.Access;
import io.druid.server.security.AuthConfig;
import io.druid.server.security.AuthenticationResult;
import io.druid.server.security.AuthorizationUtils;
import io.druid.server.security.AuthorizerMapper;
import io.druid.server.security.Escalator;
import io.druid.server.security.ForbiddenException;
import io.druid.sql.calcite.rel.DruidConvention;
import io.druid.sql.calcite.rel.DruidRel;
Expand Down Expand Up @@ -61,6 +62,7 @@
import org.apache.calcite.tools.ValidationException;
import org.apache.calcite.util.Pair;

import javax.annotation.Nullable;
import javax.servlet.http.HttpServletRequest;
import java.io.Closeable;
import java.util.ArrayList;
Expand All @@ -72,33 +74,44 @@ public class DruidPlanner implements Closeable
private final Planner planner;
private final PlannerContext plannerContext;
private final AuthorizerMapper authorizerMapper;
private final Escalator escalator;

public DruidPlanner(
DruidPlanner(
final Planner planner,
final PlannerContext plannerContext,
final AuthorizerMapper authorizerMapper,
final Escalator escalator
final AuthorizerMapper authorizerMapper
)
{
this.planner = planner;
this.plannerContext = plannerContext;
this.authorizerMapper = authorizerMapper;
this.escalator = escalator;
}

public PlannerResult plan(final String sql) throws SqlParseException, ValidationException, RelConversionException
public PlannerResult plan(
final String sql,
final HttpServletRequest request
) throws SqlParseException, ValidationException, RelConversionException, ForbiddenException
{
AuthenticationResult authenticationResult = escalator.createEscalatedAuthenticationResult();
return plan(sql, null, authenticationResult);
return plan(sql, Preconditions.checkNotNull(request, "request"), null);
}

public PlannerResult plan(
final String sql,
final HttpServletRequest request,
final AuthenticationResult authenticationResult
) throws SqlParseException, ValidationException, RelConversionException, ForbiddenException
{
return plan(sql, null, Preconditions.checkNotNull(authenticationResult, "authenticationResult"));
}

private PlannerResult plan(
final String sql,
@Nullable final HttpServletRequest request,
@Nullable final AuthenticationResult authenticationResult
) throws SqlParseException, ValidationException, RelConversionException, ForbiddenException
{
if (authenticationResult != null && request != null) {
throw new ISE("Cannot specify both 'request' and 'authenticationResult'");
}

SqlExplain explain = null;
SqlNode parsed = planner.parse(sql);
if (parsed.getKind() == SqlKind.EXPLAIN) {
Expand Down Expand Up @@ -137,8 +150,8 @@ public void close()
private PlannerResult planWithDruidConvention(
final SqlExplain explain,
final RelRoot root,
final HttpServletRequest request,
final AuthenticationResult authenticationResult
@Nullable final HttpServletRequest request,
@Nullable final AuthenticationResult authenticationResult
) throws RelConversionException, ForbiddenException
{
final DruidRel<?> druidRel = (DruidRel<?>) planner.transform(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,7 @@
import io.druid.guice.annotations.Json;
import io.druid.math.expr.ExprMacroTable;
import io.druid.server.QueryLifecycleFactory;
import io.druid.server.security.AuthConfig;
import io.druid.server.security.AuthorizerMapper;
import io.druid.server.security.Escalator;
import io.druid.sql.calcite.rel.QueryMaker;
import io.druid.sql.calcite.schema.DruidSchema;
import org.apache.calcite.avatica.util.Casing;
Expand Down Expand Up @@ -64,10 +62,7 @@ public class PlannerFactory
private final ExprMacroTable macroTable;
private final PlannerConfig plannerConfig;
private final ObjectMapper jsonMapper;

private final AuthConfig authConfig;
private final AuthorizerMapper authorizerMapper;
private final Escalator escalator;

@Inject
public PlannerFactory(
Expand All @@ -76,9 +71,7 @@ public PlannerFactory(
final DruidOperatorTable operatorTable,
final ExprMacroTable macroTable,
final PlannerConfig plannerConfig,
final AuthConfig authConfig,
final AuthorizerMapper authorizerMapper,
final Escalator escalator,
final @Json ObjectMapper jsonMapper
)
{
Expand All @@ -87,9 +80,7 @@ public PlannerFactory(
this.operatorTable = operatorTable;
this.macroTable = macroTable;
this.plannerConfig = plannerConfig;
this.authConfig = authConfig;
this.authorizerMapper = authorizerMapper;
this.escalator = escalator;
this.jsonMapper = jsonMapper;
}

Expand Down Expand Up @@ -151,8 +142,7 @@ public SqlConformance conformance()
return new DruidPlanner(
Frameworks.getPlanner(frameworkConfig),
plannerContext,
authorizerMapper,
escalator
authorizerMapper
);
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@

import com.google.common.base.Throwables;
import com.google.common.collect.ImmutableList;
import io.druid.server.security.Escalator;
import io.druid.sql.calcite.planner.DruidPlanner;
import io.druid.sql.calcite.planner.PlannerFactory;
import io.druid.sql.calcite.schema.DruidSchema;
Expand All @@ -36,11 +37,13 @@
public class DruidViewMacro implements TableMacro
{
private final PlannerFactory plannerFactory;
private final Escalator escalator;
private final String viewSql;

public DruidViewMacro(final PlannerFactory plannerFactory, final String viewSql)
public DruidViewMacro(final PlannerFactory plannerFactory, final Escalator escalator, final String viewSql)
{
this.plannerFactory = plannerFactory;
this.escalator = escalator;
this.viewSql = viewSql;
}

Expand All @@ -49,7 +52,9 @@ public TranslatableTable apply(final List<Object> arguments)
{
final RelDataType rowType;
try (final DruidPlanner planner = plannerFactory.createPlanner(null)) {
rowType = planner.plan(viewSql).rowType();
// Using an escalator here is a hack, but it's currently needed to get the row type. Ideally, some
// later refactoring would make this unnecessary, since there is no actual query going out herem.
rowType = planner.plan(viewSql, escalator.createEscalatedAuthenticationResult()).rowType();
}
catch (Exception e) {
throw Throwables.propagate(e);
Expand Down
Loading