You are viewing a plain text version of this content. The canonical link for it is here.
Posted to solr-user@lucene.apache.org by Bruno Mannina <bm...@free.fr> on 2013/11/26 16:37:06 UTC

How to request not directly my SOLR server ?

Dear All,

I show my SOLR server to a friend and its first question was:

"You can request directly your solr database from your internet 
explorer?! is it not a security problem?
each person which has your request link can use your database directly?"

So I ask the question here. I protect my admin panel but is it possible 
to protect a direct request ?

By using google, lot a result concern admin panel security but I can't 
find information about that.

Thanks for your comment,

Bruno

---
Ce courrier électronique ne contient aucun virus ou logiciel malveillant parce que la protection avast! Antivirus est active.
http://www.avast.com


Re: How to request not directly my SOLR server ?

Posted by Bruno Mannina <bm...@free.fr>.
Le 26/11/2013 18:52, Shawn Heisey a écrit :
> On 11/26/2013 8:37 AM, Bruno Mannina wrote:
>> I show my SOLR server to a friend and its first question was:
>>
>> "You can request directly your solr database from your internet 
>> explorer?! is it not a security problem?
>> each person which has your request link can use your database directly?"
>>
>> So I ask the question here. I protect my admin panel but is it 
>> possible to protect a direct request ?
>
> Don't make your Solr server directly accessible from the Internet.  
> Only make it accessible from the machines that serve your website and 
> whoever needs to administer it.
>
> Solr has no security features.  You can use the security features in 
> whatever container is running Solr, but that is outside the scope of 
> this mailing list.
>
> Thanks,
> Shawn
>
>
>
Thanks a lot for this information,

Bruno

---
Ce courrier électronique ne contient aucun virus ou logiciel malveillant parce que la protection avast! Antivirus est active.
http://www.avast.com


Re: How to request not directly my SOLR server ?

Posted by Shawn Heisey <so...@elyograg.org>.
On 11/26/2013 8:37 AM, Bruno Mannina wrote:
> I show my SOLR server to a friend and its first question was:
>
> "You can request directly your solr database from your internet 
> explorer?! is it not a security problem?
> each person which has your request link can use your database directly?"
>
> So I ask the question here. I protect my admin panel but is it 
> possible to protect a direct request ?

Don't make your Solr server directly accessible from the Internet.  Only 
make it accessible from the machines that serve your website and whoever 
needs to administer it.

Solr has no security features.  You can use the security features in 
whatever container is running Solr, but that is outside the scope of 
this mailing list.

Thanks,
Shawn