CalvinKirs opened a new pull request, #68647:
URL: https://github.com/apache/doris/pull/68647

   ### What problem does this PR solve?
   
   Issue Number: None
   
   Related PR: #65551, #66205
   
   Problem Summary:
   
   The threat model (`threat-model.md`) is what security scanners, review
   agents and triagers use to decide what a report means. Two FE settings
   were missing from it, or described only indirectly:
   
   1. `enable_all_http_auth` (FE). The model already records that it
      ships on and calls "on" the supported production posture, but it
      never says outright that production deployments must run with it
      on.
   2. `fe_meta_auth_token` (added in #65551). The model does not mention
      it at all. It is the credential for the FE-to-FE meta-service
      endpoints on port 8030 (`/image`, `/info`, `/version`, `/put`,
      `/journal_id`, `/role`, `/check`). Those endpoints sit outside the
      `/api/**` and `/rest/v2/**` surface that §4.8 (11) covers, so a
      report about them currently has no section to land in and would be
      routed as MODEL-GAP. The model also uses the words "cluster token"
      for the unrelated `token` in `doris-meta/image/VERSION`, which makes
      the two easy to confuse.
   
   This change records both settings as required for production (new
   maintainer decision M20) and routes findings about them:
   
   - §4.5a: marks `enable_all_http_auth` as required in production, adds
     a `fe_meta_auth_token` row, adds a short "FE HTTP settings required
     in production" section that explains the meta-service endpoints and
     separates this token from the VERSION-file cluster token, and
     requires the token to be set for security-testing runs.
   - §4.6: adds a trust-table row for the meta-service endpoints.
   - §4.8: states that property (11) does not cover these endpoints and
     adds property (13): with the token set, each of them must reject a
     request without the matching `token` header, and one accepted anyway
     is VALID.
   - §4.9: disclaims authentication for these endpoints while the token
     is empty (the shipped default), so such reports are
     BY-DESIGN: property-disclaimed rather than MODEL-GAP.
   - §4.10: (12) now says production must keep `enable_all_http_auth`
     on; new (13) tells operators to set the same token on every FE,
     how to confirm it (`ADMIN SHOW FRONTEND CONFIG` shows `********`
     when set), and to treat it as a secret.
   - §4.11, §4.11a, §4.12, §4.14: matching misuse pattern, known
     non-finding, change trigger, wave-6 decision record and follow-up.
   - `SECURITY.md`: asks testers to confirm the token is set on every FE
     before testing, next to the existing `enable_all_http_auth` note.
   
   The code facts cited were checked against master: `MetaService`
   (`checkFromValidFe`), the `AuthInterceptor` exclusions in
   `WebConfigurer`, the `fe_meta_auth_token` definition in `Config`, and
   the masking of sensitive values in `ConfigBase.getConfigInfo`, which
   `ADMIN SHOW FRONTEND CONFIG` uses.
   
   ### Release note
   
   None
   
   ### Check List (For Author)
   
   - Test: No need to test (documentation-only change to `threat-model.md`
     and `SECURITY.md`; no code changed)
   - Behavior changed: No
   - Does this need documentation: No (this is the documentation change;
     the deployment/upgrade guide follow-up is recorded in §4.14)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to