Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-20406

HBase Thrift HTTP - Shouldn't handle TRACE/OPTIONS methods

    XMLWordPrintableJSON

    Details

    • Type: Improvement
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 3.0.0, 2.1.0, 1.5.0
    • Component/s: security, Thrift
    • Labels:
      None
    • Hadoop Flags:
      Incompatible change
    • Release Note:
      Hide
      <!-- markdown -->
      When configured to do thrift-over-http, the HBase Thrift API Server no longer accepts the HTTP methods TRACE nor OPTIONS.
      Show
      <!-- markdown --> When configured to do thrift-over-http, the HBase Thrift API Server no longer accepts the HTTP methods TRACE nor OPTIONS.

      Description

      HBASE-10473 introduced a utility HttpServerUtil.constrainHttpMethods to prevent Jetty from answering on TRACE and OPTIONS methods. This should be added to Thrift in HTTP mode as well.

        Attachments

        1. HBASE-20406.master.002.patch
          5 kB
          Kevin Risden
        2. HBASE-20406.master.001.patch
          2 kB
          Kevin Risden

          Issue Links

            Activity

              People

              • Assignee:
                krisden Kevin Risden
                Reporter:
                krisden Kevin Risden
              • Votes:
                0 Vote for this issue
                Watchers:
                8 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: