Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Workaround
-
None
-
None
-
None
Description
/admin/zookeeper API is currently exposing security.json as-is, which can contain security credentials as well.
Proposing a configurable list for hiding elements of security.json when loaded through /admin/zookeeper.
Attachments
Issue Links
- duplicates
-
SOLR-7890 By default require admin rights to access /security.json in ZK
- Resolved
- is duplicated by
-
SOLR-11623 Every request handler in Solr should implement PermissionNameProvider interface
- Closed
- relates to
-
SOLR-13942 /api/cluster/zk/* to fetch raw ZK data
- Closed
-
SOLR-15768 Tune zookeeper request handler permissions (8x)
- Closed