elephone-184 opened a new pull request, #4969:
URL: https://github.com/apache/rocketmq-dashboard/pull/4969
## What is the purpose of the change
In enterprise environments, complex RocketMQ ACL policies are provisioned
across clusters. Over time, policies accumulate security misconfigurations such
as unrestricted wildcard source IP expressions (`*` or `0.0.0.0/0`), syntax
issues, overlapping IP ranges on the same resource, and inadvertent permission
grants on sensitive system resources (such as `%RETRY%`, `%DLQ%`, `TBW102`,
etc.).
This PR introduces an automated ACL Security Auditor (`AclSecurityAuditor`)
and audit report model:
1. `AclAuditReportVO` & `AclAuditFindingVO`: Standardized domain VO
capturing metrics (wildcard counts, overlapping rule counts, syntax warning
counts) and structured findings with severity levels (`CRITICAL`, `HIGH`,
`MEDIUM`).
2. `AclSecurityAuditor`: Analyzes real ACL rules fetched from instance
configurations, detects IP intervals and mutual overlaps, identifies wildcard
exposures, and audits access against sensitive system resource prefixes.
3. `AclService` & `AclController`: Connects the auditor through
`/api/acl/rules/audit?instanceId={id}`, supporting both Apache and Tencent
instances.
4. Comprehensive unit tests covering rule interval extraction, edge-case
evaluations, and controller/service integration.
## Brief changelog
- Add `AclAuditReportVO.java` domain model.
- Add `AclSecurityAuditor.java` rule security analysis engine.
- Add `/api/acl/rules/audit` endpoint in `AclController` and `auditAclRules`
in `AclService`.
- Add `AclSecurityAuditorTest.java`, and expand `AclControllerTest.java` and
`AclServiceTest.java`.
## Verifying this change
- `AclSecurityAuditorTest`: verifies wildcard exposure detection,
overlapping subnet detection, syntax warnings, and sensitive resource checks.
- `AclControllerTest`: verifies `/api/acl/rules/audit` HTTP response mapping.
- `AclServiceTest`: verifies integration between `AclService` and
`AclSecurityAuditor`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]