jbonofre opened a new pull request, #2639:
URL: https://github.com/apache/activemq/pull/2639

   Default configuration changes for the web console and the Jolokia REST API.
   
   ## `conf/jolokia-access.xml`
   
   - `<allow>` lists the read-only broker operations explicitly (browse, 
queries, health, scheduled job listing, cursor state) instead of a wildcard on 
`org.apache.activemq:*`. Jolokia consults `<allow>` only for command types that 
are not in `<commands>` (write, exec) and does not consult `<deny>` for them, 
so the list has to be explicit. The file now documents how the three sections 
combine.
   - `<cors>` lists the console's loopback origins (`localhost`, `127.0.0.1`, 
`[::1]` on the default http and https ports) for strict checking.
   - Operation names in `<deny>` end with `*` so they also match a name sent 
with its signature, e.g. `purge()`.
   
   ## `conf/jetty-spring.properties` and `JettyServerBean`
   
   - `jetty.http.host` and `jetty.ssl.host` are set to `127.0.0.1`, so the 
connectors bind loopback by default as they did before the move to 
`conf/jetty/*.xml`.
   - `-Djetty.host=<address>` overrides both again. The Docker entrypoint 
passes it.
   
   ## Behaviour changes
   
   - Write and exec requests through Jolokia are limited to the listed 
read-only operations. To open another one, add it to `<allow>`.
   - Jolokia clients must send an `Origin` header matching an `<allow-origin>` 
entry. Add the scheme, host and port the console is reached through if it 
differs from the defaults.
   - Installations that keep their own `jetty-spring.properties` need to add 
the two host lines to get the loopback binding.
   
   ## Tests
   
   - `JolokiaAccessPolicyTest` evaluates the shipped policy with Jolokia's 
`PolicyRestrictor`: every operation of the broker MBean interfaces (bare name 
and with signature), attribute writes and reads, and origins.
   - `JettyBindAddressTest` applies the shipped Jetty XML files and properties 
and checks the connector hosts.
   - `JettyServerBeanTest` covers the configured host and the `-Djetty.host` 
override.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
For further information, visit: https://activemq.apache.org/contact


Reply via email to