[ 
https://issues.apache.org/jira/browse/BROOKLYN-293?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15320310#comment-15320310
 ] 

ASF GitHub Bot commented on BROOKLYN-293:
-----------------------------------------

GitHub user aledsage opened a pull request:

    https://github.com/apache/brooklyn-server/pull/188

    BROOKLYN-293: web-console disables directory listing

    

You can merge this pull request into a Git repository by running:

    $ git pull https://github.com/aledsage/brooklyn-server BROOKLYN-293

Alternatively you can review and apply these changes as the patch at:

    https://github.com/apache/brooklyn-server/pull/188.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

    This closes #188
    
----
commit ea11d67144cfaf631cfe4cea031e934002cc431a
Author: Aled Sage <[email protected]>
Date:   2016-06-08T09:46:17Z

    BROOKLYN-293: web-console disables directory listing

----


> Web-console should not allow directory listing
> ----------------------------------------------
>
>                 Key: BROOKLYN-293
>                 URL: https://issues.apache.org/jira/browse/BROOKLYN-293
>             Project: Brooklyn
>          Issue Type: Improvement
>    Affects Versions: 0.9.0
>            Reporter: Aled Sage
>            Priority: Minor
>
> A customer's security audit spotted that directory browsing is enabled in the 
> Brooklyn web-console. For example, http://localhost:8081/assets.
> In general, it is more secure to forbid directory listing.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to