Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-5135

Whitelist legit usages of loginAdministrative and administrative ResourceResolver

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • JCR Base 2.4.2
    • JCR
    • None

    Description

      AbstractSlingRepositoryManager contains a method that disable loginAdministrative support

          /**
           * Returns whether to disable the
           * {@code SlingRepository.loginAdministrative} method or not.
           *
           * @return {@code true} if {@code SlingRepository.loginAdministrative} is
           *         disabled.
           */
          public final boolean isDisableLoginAdministrative() 
      

      This is a global configuration. It would be nice to have an extension of such mechanism that contains a white list of (few) legit usage of loginAdministrative

      Attachments

        1. SLING-5135.patch
          32 kB
          Bertrand Delacretaz
        2. SLING-5135.patch
          16 kB
          Bertrand Delacretaz

        Issue Links

          Activity

            People

              jsedding Julian Sedding
              asanso Antonio Sanso
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: