Uploaded image for project: 'Hadoop HDFS'
  1. Hadoop HDFS
  2. HDFS-12158

Secondary Namenode's web interface lack configs for X-FRAME-OPTIONS protection

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.9.0, 3.0.0-beta1, 2.8.2
    • Component/s: namenode
    • Labels:
      None
    • Target Version/s:
    • Hadoop Flags:
      Reviewed

      Description

      HDFS-10579 adds X-FRAME-OPTIONS protection to Namenode and Datanode.
      This is also needed for Secondary Namenode as well.

      Seondary Namenode misses X-FRAME-OPTIONS protection

      [root@f0e12b63907e opt]# curl -I http://127.0.0.1:50090/index.html
      HTTP/1.1 200 OK
      Cache-Control: no-cache
      Expires: Tue, 18 Jul 2017 20:13:53 GMT
      Date: Tue, 18 Jul 2017 20:13:53 GMT
      Pragma: no-cache
      Expires: Tue, 18 Jul 2017 20:13:53 GMT
      Date: Tue, 18 Jul 2017 20:13:53 GMT
      Pragma: no-cache
      Content-Type: text/html; charset=utf-8
      Last-Modified: Mon, 12 Jun 2017 13:15:41 GMT
      Content-Length: 1083
      Accept-Ranges: bytes
      Server: Jetty(6.1.26)
      

      Primary Namenode offers X-FRAME-OPTIONS protection

      [root@f0e12b63907e opt]# curl -I http://127.0.0.1:50070/index.html
      HTTP/1.1 200 OK
      Cache-Control: no-cache
      Expires: Tue, 18 Jul 2017 20:14:04 GMT
      Date: Tue, 18 Jul 2017 20:14:04 GMT
      Pragma: no-cache
      Expires: Tue, 18 Jul 2017 20:14:04 GMT
      Date: Tue, 18 Jul 2017 20:14:04 GMT
      Pragma: no-cache
      Content-Type: text/html; charset=utf-8
      X-FRAME-OPTIONS: SAMEORIGIN
      Last-Modified: Mon, 12 Jun 2017 13:15:41 GMT
      Content-Length: 1079
      Accept-Ranges: bytes
      Server: Jetty(6.1.26)
      
      1. HDFS-12158.001.patch
        3 kB
        Mukul Kumar Singh

        Activity

        Hide
        hudson Hudson added a comment -

        SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #12033 (See https://builds.apache.org/job/Hadoop-trunk-Commit/12033/)
        HDFS-12158. Secondary Namenode's web interface lack configs for (aengineer: rev 413b23eb04eee24275257ab462133e0818f87449)

        • (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/namenode/TestNameNodeHttpServerXFrame.java
        • (edit) hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/namenode/SecondaryNameNode.java
        Show
        hudson Hudson added a comment - SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #12033 (See https://builds.apache.org/job/Hadoop-trunk-Commit/12033/ ) HDFS-12158 . Secondary Namenode's web interface lack configs for (aengineer: rev 413b23eb04eee24275257ab462133e0818f87449) (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/namenode/TestNameNodeHttpServerXFrame.java (edit) hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/namenode/SecondaryNameNode.java
        Hide
        anu Anu Engineer added a comment -

        Mukul Kumar Singh Thanks for the contribution. I have committed this to trunk, branch-2, and branch-2.8.2

        Show
        anu Anu Engineer added a comment - Mukul Kumar Singh Thanks for the contribution. I have committed this to trunk, branch-2, and branch-2.8.2
        Hide
        anu Anu Engineer added a comment -

        +1, I will commit this shortly.

        Show
        anu Anu Engineer added a comment - +1, I will commit this shortly.
        Hide
        hadoopqa Hadoop QA added a comment -
        -1 overall



        Vote Subsystem Runtime Comment
        0 reexec 0m 16s Docker mode activated.
              Prechecks
        +1 @author 0m 0s The patch does not contain any @author tags.
        +1 test4tests 0m 0s The patch appears to include 1 new or modified test files.
              trunk Compile Tests
        +1 mvninstall 13m 39s trunk passed
        +1 compile 0m 58s trunk passed
        +1 checkstyle 0m 37s trunk passed
        +1 mvnsite 0m 55s trunk passed
        -1 findbugs 1m 42s hadoop-hdfs-project/hadoop-hdfs in trunk has 10 extant Findbugs warnings.
        +1 javadoc 0m 41s trunk passed
              Patch Compile Tests
        +1 mvninstall 0m 55s the patch passed
        +1 compile 0m 54s the patch passed
        +1 javac 0m 54s the patch passed
        +1 checkstyle 0m 35s the patch passed
        +1 mvnsite 0m 59s the patch passed
        +1 whitespace 0m 0s The patch has no whitespace issues.
        +1 findbugs 1m 53s the patch passed
        +1 javadoc 0m 42s the patch passed
              Other Tests
        -1 unit 92m 37s hadoop-hdfs in the patch failed.
        +1 asflicense 0m 20s The patch does not generate ASF License warnings.
        119m 11s



        Reason Tests
        Failed junit tests hadoop.hdfs.server.namenode.TestAuditLogs
          hadoop.hdfs.TestDFSStripedOutputStreamWithFailure070
          hadoop.hdfs.TestDFSStripedOutputStreamWithFailure080
          hadoop.hdfs.server.namenode.ha.TestPipelinesFailover
          hadoop.hdfs.TestDFSStripedOutputStreamWithFailure150



        Subsystem Report/Notes
        Docker Image:yetus/hadoop:14b5c93
        JIRA Issue HDFS-12158
        JIRA Patch URL https://issues.apache.org/jira/secure/attachment/12877996/HDFS-12158.001.patch
        Optional Tests asflicense compile javac javadoc mvninstall mvnsite unit findbugs checkstyle
        uname Linux 8db621cbdc82 3.13.0-123-generic #172-Ubuntu SMP Mon Jun 26 18:04:35 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
        Build tool maven
        Personality /testptch/hadoop/patchprocess/precommit/personality/provided.sh
        git revision trunk / 2843c68
        Default Java 1.8.0_131
        findbugs v3.1.0-RC1
        findbugs https://builds.apache.org/job/PreCommit-HDFS-Build/20338/artifact/patchprocess/branch-findbugs-hadoop-hdfs-project_hadoop-hdfs-warnings.html
        unit https://builds.apache.org/job/PreCommit-HDFS-Build/20338/artifact/patchprocess/patch-unit-hadoop-hdfs-project_hadoop-hdfs.txt
        Test Results https://builds.apache.org/job/PreCommit-HDFS-Build/20338/testReport/
        modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs
        Console output https://builds.apache.org/job/PreCommit-HDFS-Build/20338/console
        Powered by Apache Yetus 0.6.0-SNAPSHOT http://yetus.apache.org

        This message was automatically generated.

        Show
        hadoopqa Hadoop QA added a comment - -1 overall Vote Subsystem Runtime Comment 0 reexec 0m 16s Docker mode activated.       Prechecks +1 @author 0m 0s The patch does not contain any @author tags. +1 test4tests 0m 0s The patch appears to include 1 new or modified test files.       trunk Compile Tests +1 mvninstall 13m 39s trunk passed +1 compile 0m 58s trunk passed +1 checkstyle 0m 37s trunk passed +1 mvnsite 0m 55s trunk passed -1 findbugs 1m 42s hadoop-hdfs-project/hadoop-hdfs in trunk has 10 extant Findbugs warnings. +1 javadoc 0m 41s trunk passed       Patch Compile Tests +1 mvninstall 0m 55s the patch passed +1 compile 0m 54s the patch passed +1 javac 0m 54s the patch passed +1 checkstyle 0m 35s the patch passed +1 mvnsite 0m 59s the patch passed +1 whitespace 0m 0s The patch has no whitespace issues. +1 findbugs 1m 53s the patch passed +1 javadoc 0m 42s the patch passed       Other Tests -1 unit 92m 37s hadoop-hdfs in the patch failed. +1 asflicense 0m 20s The patch does not generate ASF License warnings. 119m 11s Reason Tests Failed junit tests hadoop.hdfs.server.namenode.TestAuditLogs   hadoop.hdfs.TestDFSStripedOutputStreamWithFailure070   hadoop.hdfs.TestDFSStripedOutputStreamWithFailure080   hadoop.hdfs.server.namenode.ha.TestPipelinesFailover   hadoop.hdfs.TestDFSStripedOutputStreamWithFailure150 Subsystem Report/Notes Docker Image:yetus/hadoop:14b5c93 JIRA Issue HDFS-12158 JIRA Patch URL https://issues.apache.org/jira/secure/attachment/12877996/HDFS-12158.001.patch Optional Tests asflicense compile javac javadoc mvninstall mvnsite unit findbugs checkstyle uname Linux 8db621cbdc82 3.13.0-123-generic #172-Ubuntu SMP Mon Jun 26 18:04:35 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux Build tool maven Personality /testptch/hadoop/patchprocess/precommit/personality/provided.sh git revision trunk / 2843c68 Default Java 1.8.0_131 findbugs v3.1.0-RC1 findbugs https://builds.apache.org/job/PreCommit-HDFS-Build/20338/artifact/patchprocess/branch-findbugs-hadoop-hdfs-project_hadoop-hdfs-warnings.html unit https://builds.apache.org/job/PreCommit-HDFS-Build/20338/artifact/patchprocess/patch-unit-hadoop-hdfs-project_hadoop-hdfs.txt Test Results https://builds.apache.org/job/PreCommit-HDFS-Build/20338/testReport/ modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs Console output https://builds.apache.org/job/PreCommit-HDFS-Build/20338/console Powered by Apache Yetus 0.6.0-SNAPSHOT http://yetus.apache.org This message was automatically generated.

          People

          • Assignee:
            msingh Mukul Kumar Singh
            Reporter:
            msingh Mukul Kumar Singh
          • Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development