Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-15194

JWTIssuerConfig only allows HTTPS urls, not HTTP, which is overly strict.

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 9.0, 8.8.1
    • 9.0, 8.9
    • security
    • None

    Description

      Setting up JWT should always be done with HTTPS urls, but especially in dev and test, require HTTPS is too much.  

      Let Solr relax a bit, and log a warning if the url is HTTP versus HTTPS.

       

      Keycloak, out of the box for example doesn't have SSL enabled.

      Attachments

        Issue Links

          Activity

            People

              epugh Eric Pugh
              epugh Eric Pugh
              Votes:
              1 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 4h
                  4h