Uploaded image for project: 'Jackrabbit Oak'
  1. Jackrabbit Oak
  2. OAK-9493

Use index option to for security relevant queries

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • core, security
    • None

    Description

      while investigating a potential issue with principal-lookup thomasm made me aware of the index-option (see https://jackrabbit.apache.org/oak/docs/query/query-engine.html#Query_Option_Index_Tag) that allows to enforce the usage of a dedicated index when executing a query.

      i would like to review all security relevant queries and add the index option for those that are known to be relevant for consistency and/or security.

      cc: kpauls, fyi as this relates to the recent discussion regarding system-user-validation upon service-user-mapping in Sling.

      Attachments

        Activity

          People

            angela Angela Schreiber
            angela Angela Schreiber
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: