[ 
https://issues.apache.org/jira/browse/HDFS-12273?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16168593#comment-16168593
 ] 

Chris Douglas commented on HDFS-12273:
--------------------------------------

bq. Regarding the note in the doc, I could add it here or HDFS-12381 as a 
general comment on security and not only about the Web UI.
Adding it to HDFS-12381 is simplest.

bq.  XSS isn't quite related to HDFS-12284, so if at all you want to postpone 
the analysis, would it make sense to file a different JIRA?
Sure, fair enough. Even if "harden the federation UI" is closed without 
requiring any code, it'd be useful for tracking.

If we defer hardening the UI to after the merge, the current patch seems fine 
to me.

> Federation UI
> -------------
>
>                 Key: HDFS-12273
>                 URL: https://issues.apache.org/jira/browse/HDFS-12273
>             Project: Hadoop HDFS
>          Issue Type: Sub-task
>          Components: fs
>            Reporter: Íñigo Goiri
>            Assignee: Íñigo Goiri
>             Fix For: HDFS-10467
>
>         Attachments: federationUI-1.png, federationUI-2.png, 
> federationUI-3.png, HDFS-12273-HDFS-10467-000.patch, 
> HDFS-12273-HDFS-10467-001.patch, HDFS-12273-HDFS-10467-002.patch, 
> HDFS-12273-HDFS-10467-003.patch, HDFS-12273-HDFS-10467-004.patch
>
>
> Add the Web UI to the Router to expose the status of the federated cluster. 
> It includes the federation metrics.



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to