Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-27792

Guard Master/RS Dump Servlet behind admin walls

    XMLWordPrintableJSON

Details

    Description

      Currently RSDumpServlet and MasterDumpServlet do not require any check for whether the user has privileges to access to instrumentation servlets.

      This is unlike other servlets like ProfileServlet, ConfServlet, JMXJsonServlet etc. which are guarded by admin checks.

      Goal of this JIRA is to add similar check for RS and Master Dump Servlet. Post this change only admins will be able to access RSDumpServlet and MasterDumpServlet, if hadoop.security.instrumentation.requires.admin is enabled.

      Attachments

        Activity

          People

            nihaljain.cs Nihal Jain
            nihaljain.cs Nihal Jain
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: