[
https://issues.apache.org/jira/browse/HADOOP-3342?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12594401#action_12594401
]
Enis Soztutar commented on HADOOP-3342:
---------------------------------------
As far as I remember killing job is already a two step process, when we click
kill job, the page is reloaded to confirm the killing action. I'm OK with the
POST check.
> Better safety of killing jobs via web interface
> -----------------------------------------------
>
> Key: HADOOP-3342
> URL: https://issues.apache.org/jira/browse/HADOOP-3342
> Project: Hadoop Core
> Issue Type: Improvement
> Affects Versions: 0.16.3
> Reporter: Daniel Naber
> Priority: Minor
> Attachments: kill-job.diff
>
>
> Although the option to kill jobs via the web interface is turned off by
> default, it should be made safer. Currently the "kill" action and its
> confirmation is just a link so it could be triggered by a crawler or by a
> browser's pre-fetching mechanism. The attached patch makes it work only with
> "POST" so that e.g. well-behaved crawlers shouldn't be able to access it.
--
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.