You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@doris.apache.org by GitBox <gi...@apache.org> on 2022/10/10 11:01:44 UTC

[GitHub] [doris] pengxiangyu opened a new pull request, #13255: [feature](config)Add hide config to hide config in webserver for safety.

pengxiangyu opened a new pull request, #13255:
URL: https://github.com/apache/doris/pull/13255

   # Proposed changes
   
   Issue Number: close #13254
   
   ## Problem summary
   
   Webserver on BE has no authorization verification. Anyone can get the config for be.
   It is not safe for online system.
   So I need to add a parameter to hide the config.
   
   ## Checklist(Required)
   
   1. Does it affect the original behavior: 
       - [ ] Yes
       - [ ] No
       - [ ] I don't know
   2. Has unit tests been added:
       - [ ] Yes
       - [ ] No
       - [ ] No Need
   3. Has document been added or modified:
       - [ ] Yes
       - [ ] No
       - [ ] No Need
   4. Does it need to update dependencies:
       - [ ] Yes
       - [ ] No
   5. Are there any changes that cannot be rolled back:
       - [ ] Yes (If Yes, please explain WHY)
       - [ ] No
   
   ## Further comments
   
   If this is a relatively large or complex change, kick off the discussion at [dev@doris.apache.org](mailto:dev@doris.apache.org) by explaining why you chose the solution you did and what alternatives you considered, etc...
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org
For additional commands, e-mail: commits-help@doris.apache.org


[GitHub] [doris] yiguolei commented on pull request #13255: [feature](config)Add hide config to hide config in webserver for safety.

Posted by GitBox <gi...@apache.org>.
yiguolei commented on PR #13255:
URL: https://github.com/apache/doris/pull/13255#issuecomment-1274245094

   If config's security is a problem, then why not add a config to disable all http APIs in BE?


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org
For additional commands, e-mail: commits-help@doris.apache.org


[GitHub] [doris] pengxiangyu merged pull request #13255: [feature](config)Add hide config to hide config in webserver for safety.

Posted by GitBox <gi...@apache.org>.
pengxiangyu merged PR #13255:
URL: https://github.com/apache/doris/pull/13255


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org
For additional commands, e-mail: commits-help@doris.apache.org


[GitHub] [doris] github-actions[bot] commented on pull request #13255: [feature](config)Add hide config to hide config in webserver for safety.

Posted by GitBox <gi...@apache.org>.
github-actions[bot] commented on PR #13255:
URL: https://github.com/apache/doris/pull/13255#issuecomment-1274755505

   PR approved by at least one committer and no changes requested.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org
For additional commands, e-mail: commits-help@doris.apache.org


[GitHub] [doris] github-actions[bot] commented on pull request #13255: [feature](config)Add hide config to hide config in webserver for safety.

Posted by GitBox <gi...@apache.org>.
github-actions[bot] commented on PR #13255:
URL: https://github.com/apache/doris/pull/13255#issuecomment-1274755572

   PR approved by anyone and no changes requested.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org
For additional commands, e-mail: commits-help@doris.apache.org


[GitHub] [doris] pengxiangyu commented on pull request #13255: [feature](config)Add hide config to hide config in webserver for safety.

Posted by GitBox <gi...@apache.org>.
pengxiangyu commented on PR #13255:
URL: https://github.com/apache/doris/pull/13255#issuecomment-1274411093

   > If config's security is a problem, then why not add a config to disable all http APIs in BE?
   The other webserver pages are still useful, and they are only monitor infomations.
   Webserver is still useful in Be, shutdown will cause BE not work suitable.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@doris.apache.org
For additional commands, e-mail: commits-help@doris.apache.org