Hello all,

I am using CAS 5.0.3 built by Gradle overlay project and I am a bit 
confused about mission of /status/metrics page.

If it was designed to provide machine-readable gauges/counters/meters and 
make them available for publicity for some reasons, then everything is OK.

But if it was designed to be hidden from publicity, then it seems to me 
there is a bug. 

Let me explain a little bit.
I've set the property

cas.adminPagesSecurity.ip=127\\.0\\.0\\.1

and now all /status[/*] pages on our development server are forbidden and 
display 401 page, but /status/metrics still displays usual JSON content.

Any thoughts?

Thanks,
Yauheni

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/a1baa9db-2f36-4c26-9f14-5f497ae7ce22%40apereo.org.

Reply via email to