You are viewing a plain text version of this content. The canonical link for it is here.
Posted to reviews@aurora.apache.org by Maxim Khutornenko <ma...@apache.org> on 2015/06/30 20:46:06 UTC

Review Request 36060: Disabling h2 console by default.

-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/36060/
-----------------------------------------------------------

Review request for Aurora and Kevin Sweeney.


Repository: aurora


Description
-------

H2 console gives direct access (including modifications and deletions) to all scheduler data. This is too powerful to be ON by default especially when using scheduler in unsecure mode.


Diffs
-----

  examples/vagrant/upstart/aurora-scheduler-kerberos.conf 3c9e13b52fd3f72ddf20c7869b5175761ac879cb 
  src/main/java/org/apache/aurora/scheduler/http/H2ConsoleModule.java a44ea08950b9d4b33503f4cfc6e28a32c619b3c8 
  src/test/java/org/apache/aurora/scheduler/http/H2ConsoleModuleIT.java 9536fe3c484329066d8939edc40fa32525880ef5 
  src/test/java/org/apache/aurora/scheduler/http/api/security/HttpSecurityIT.java 53ba949691768078ac17846b70d1baf440c444d4 

Diff: https://reviews.apache.org/r/36060/diff/


Testing
-------


Thanks,

Maxim Khutornenko


Re: Review Request 36060: Disabling h2 console by default.

Posted by Kevin Sweeney <ke...@apache.org>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/36060/#review89948
-----------------------------------------------------------

Ship it!


Ship It!

- Kevin Sweeney


On June 30, 2015, 11:46 a.m., Maxim Khutornenko wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/36060/
> -----------------------------------------------------------
> 
> (Updated June 30, 2015, 11:46 a.m.)
> 
> 
> Review request for Aurora and Kevin Sweeney.
> 
> 
> Repository: aurora
> 
> 
> Description
> -------
> 
> H2 console gives direct access (including modifications and deletions) to all scheduler data. This is too powerful to be ON by default especially when using scheduler in unsecure mode.
> 
> 
> Diffs
> -----
> 
>   examples/vagrant/upstart/aurora-scheduler-kerberos.conf 3c9e13b52fd3f72ddf20c7869b5175761ac879cb 
>   src/main/java/org/apache/aurora/scheduler/http/H2ConsoleModule.java a44ea08950b9d4b33503f4cfc6e28a32c619b3c8 
>   src/test/java/org/apache/aurora/scheduler/http/H2ConsoleModuleIT.java 9536fe3c484329066d8939edc40fa32525880ef5 
>   src/test/java/org/apache/aurora/scheduler/http/api/security/HttpSecurityIT.java 53ba949691768078ac17846b70d1baf440c444d4 
> 
> Diff: https://reviews.apache.org/r/36060/diff/
> 
> 
> Testing
> -------
> 
> 
> Thanks,
> 
> Maxim Khutornenko
> 
>


Re: Review Request 36060: Disabling h2 console by default.

Posted by Aurora ReviewBot <wf...@apache.org>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/36060/#review89950
-----------------------------------------------------------

Ship it!


Master (a1af1f6) is green with this patch.
  ./build-support/jenkins/build.sh

I will refresh this build result if you post a review containing "@ReviewBot retry"

- Aurora ReviewBot


On June 30, 2015, 6:46 p.m., Maxim Khutornenko wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/36060/
> -----------------------------------------------------------
> 
> (Updated June 30, 2015, 6:46 p.m.)
> 
> 
> Review request for Aurora and Kevin Sweeney.
> 
> 
> Repository: aurora
> 
> 
> Description
> -------
> 
> H2 console gives direct access (including modifications and deletions) to all scheduler data. This is too powerful to be ON by default especially when using scheduler in unsecure mode.
> 
> 
> Diffs
> -----
> 
>   examples/vagrant/upstart/aurora-scheduler-kerberos.conf 3c9e13b52fd3f72ddf20c7869b5175761ac879cb 
>   src/main/java/org/apache/aurora/scheduler/http/H2ConsoleModule.java a44ea08950b9d4b33503f4cfc6e28a32c619b3c8 
>   src/test/java/org/apache/aurora/scheduler/http/H2ConsoleModuleIT.java 9536fe3c484329066d8939edc40fa32525880ef5 
>   src/test/java/org/apache/aurora/scheduler/http/api/security/HttpSecurityIT.java 53ba949691768078ac17846b70d1baf440c444d4 
> 
> Diff: https://reviews.apache.org/r/36060/diff/
> 
> 
> Testing
> -------
> 
> 
> Thanks,
> 
> Maxim Khutornenko
> 
>