[ 
https://issues.apache.org/jira/browse/SOLR-10418?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15965650#comment-15965650
 ] 

Shalin Shekhar Mangar commented on SOLR-10418:
----------------------------------------------

Can you please ensure that we don't expose sensitive information such as the 
SSL keystore/truststore through this API? It'd be nice to add an optional 
blacklist of system properties to the metric handler that should never be 
exposed.

> metrics should return JVM system properties
> -------------------------------------------
>
>                 Key: SOLR-10418
>                 URL: https://issues.apache.org/jira/browse/SOLR-10418
>             Project: Solr
>          Issue Type: Improvement
>      Security Level: Public(Default Security Level. Issues are Public) 
>          Components: metrics
>            Reporter: Noble Paul
>            Assignee: Andrzej Bialecki 
>         Attachments: SOLR-10418.patch
>
>
> We need to stop using the custom solution used in rules and start using 
> metrics for everything



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to