[ 
https://issues.apache.org/jira/browse/FLINK-21108?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17303017#comment-17303017
 ] 

Scott McCallen commented on FLINK-21108:
----------------------------------------

[~xexplorer]  That's good news! We are planning to use a proxy in front of the 
dashboard UI and Rest API. The proxy will have authentication enabled, the same 
as discussed earlier in the comments. We will be able to enable this when the 
Flink client code can pass along a username & password in the HTTP requests.

I'm not a Flink contributor, but have been using Flink for a while. So for what 
it's worth, I also reviewed your PR and it made sense to me. Seems reasonable 
enough to expand in the future, to support other authentication mechanisms if 
desired. 

Please let me know if I can be of any help to get the PR part of the next 
release. Thanks!

> Flink runtime rest server and history server webmonitor do not require 
> authentication.
> --------------------------------------------------------------------------------------
>
>                 Key: FLINK-21108
>                 URL: https://issues.apache.org/jira/browse/FLINK-21108
>             Project: Flink
>          Issue Type: New Feature
>          Components: Runtime / REST, Runtime / Web Frontend
>            Reporter: Xiaoguang Sun
>            Assignee: Xiaoguang Sun
>            Priority: Major
>              Labels: pull-request-available
>
> Flink runtime rest server and history server webmonitor do not require 
> authentication. At certain scenarios, prohibiting unauthorized access is 
> desired. Http basic authentication can be used here.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to