mlevkov commented on issue #3802:
URL: https://github.com/apache/iggy/issues/3802#issuecomment-5444562362
One more reach for this API that the loopback default does not contain, found
while documenting the exposure for #3804.
`POST /{sinks,sources}/{key}/restart` takes no body and no `content-type`
(`api/sink.rs::restart_sink` extracts only `State` and `Path`), which makes
it a
CORS-simple request. A page can issue it with `mode: 'no-cors'` and the
browser
sends it whatever `[http.cors]` says, because CORS gates reading a response
rather than issuing a request. So on the shipped defaults - `enabled = true`,
`api_key = ""`, loopback `address`, `cors.enabled = false` - any page the
operator visits can restart any connector. Chrome's private network access
blocks the public-origin case; Firefox and Safari do not, and a page served
from
a local origin bypasses it everywhere.
This is not a separate bug so much as a reason the first suggested fix above
matters more than it looks. Redacting the config responses closes the
disclosure, but it does not close this: gating the mutating routes on a
configured `api_key` regardless of the global default closes both. It is also
the one part of the exposure no startup warning can help with, since it is
true
of the defaults rather than of an edit an operator made - #3804 warns on the
three departures and documents this one in the runtime README instead.
If you would rather have an `Origin` / `Sec-Fetch-Site` check on
state-changing
routes than an unconditional key requirement, that would close it too and
would
not change the default posture. Happy to take either as a follow-up.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]