mlevkov commented on issue #3802:
URL: https://github.com/apache/iggy/issues/3802#issuecomment-5444562362

   One more reach for this API that the loopback default does not contain, found
   while documenting the exposure for #3804.
   
   `POST /{sinks,sources}/{key}/restart` takes no body and no `content-type`
   (`api/sink.rs::restart_sink` extracts only `State` and `Path`), which makes 
it a
   CORS-simple request. A page can issue it with `mode: 'no-cors'` and the 
browser
   sends it whatever `[http.cors]` says, because CORS gates reading a response
   rather than issuing a request. So on the shipped defaults - `enabled = true`,
   `api_key = ""`, loopback `address`, `cors.enabled = false` - any page the
   operator visits can restart any connector. Chrome's private network access
   blocks the public-origin case; Firefox and Safari do not, and a page served 
from
   a local origin bypasses it everywhere.
   
   This is not a separate bug so much as a reason the first suggested fix above
   matters more than it looks. Redacting the config responses closes the
   disclosure, but it does not close this: gating the mutating routes on a
   configured `api_key` regardless of the global default closes both. It is also
   the one part of the exposure no startup warning can help with, since it is 
true
   of the defaults rather than of an edit an operator made - #3804 warns on the
   three departures and documents this one in the runtime README instead.
   
   If you would rather have an `Origin` / `Sec-Fetch-Site` check on 
state-changing
   routes than an unconditional key requirement, that would close it too and 
would
   not change the default posture. Happy to take either as a follow-up.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to