Details

    • Sub-task
    • Status: Open
    • Major
    • Resolution: Unresolved
    • Slider 0.70
    • None
    • security, Web & REST
    • None
    • Slider December #1

    Description

      SLIDER-710 re-opened a back door for the ws/* REST operations, as the YARN proxy doesn't support it.
      When YARN does, this back door must be blocked, otherwise unauthed users can manipulate slider clusters.
      This is a simple matter of flipping a switch in org/apache/slider/slider.xml, along with test runs to verify that it is closed.

      Time estimate is for functional test completion

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              stevel@apache.org Steve Loughran
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:

                Time Tracking

                  Estimated:
                  Original Estimate - 3h
                  3h
                  Remaining:
                  Remaining Estimate - 3h
                  3h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified