elephone-184 opened a new pull request, #4969:
URL: https://github.com/apache/rocketmq-dashboard/pull/4969

   ## What is the purpose of the change
   
   In enterprise environments, complex RocketMQ ACL policies are provisioned 
across clusters. Over time, policies accumulate security misconfigurations such 
as unrestricted wildcard source IP expressions (`*` or `0.0.0.0/0`), syntax 
issues, overlapping IP ranges on the same resource, and inadvertent permission 
grants on sensitive system resources (such as `%RETRY%`, `%DLQ%`, `TBW102`, 
etc.).
   
   This PR introduces an automated ACL Security Auditor (`AclSecurityAuditor`) 
and audit report model:
   1. `AclAuditReportVO` & `AclAuditFindingVO`: Standardized domain VO 
capturing metrics (wildcard counts, overlapping rule counts, syntax warning 
counts) and structured findings with severity levels (`CRITICAL`, `HIGH`, 
`MEDIUM`).
   2. `AclSecurityAuditor`: Analyzes real ACL rules fetched from instance 
configurations, detects IP intervals and mutual overlaps, identifies wildcard 
exposures, and audits access against sensitive system resource prefixes.
   3. `AclService` & `AclController`: Connects the auditor through 
`/api/acl/rules/audit?instanceId={id}`, supporting both Apache and Tencent 
instances.
   4. Comprehensive unit tests covering rule interval extraction, edge-case 
evaluations, and controller/service integration.
   
   ## Brief changelog
   
   - Add `AclAuditReportVO.java` domain model.
   - Add `AclSecurityAuditor.java` rule security analysis engine.
   - Add `/api/acl/rules/audit` endpoint in `AclController` and `auditAclRules` 
in `AclService`.
   - Add `AclSecurityAuditorTest.java`, and expand `AclControllerTest.java` and 
`AclServiceTest.java`.
   
   ## Verifying this change
   
   - `AclSecurityAuditorTest`: verifies wildcard exposure detection, 
overlapping subnet detection, syntax warnings, and sensitive resource checks.
   - `AclControllerTest`: verifies `/api/acl/rules/audit` HTTP response mapping.
   - `AclServiceTest`: verifies integration between `AclService` and 
`AclSecurityAuditor`.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to