[ 
https://issues.apache.org/jira/browse/KUDU-1896?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Todd Lipcon resolved KUDU-1896.
-------------------------------
       Resolution: Fixed
         Assignee: Todd Lipcon
    Fix Version/s: 1.3.0

https://gerrit.cloudera.org/#/c/6234/ added the ability to disable the web UI.

The above note wasn't quite right - Hao's working on adding test coverage for 
htpasswd, but the support is already there. So, let's call this one done.

> enable redaction of data in web UI/tracing
> ------------------------------------------
>
>                 Key: KUDU-1896
>                 URL: https://issues.apache.org/jira/browse/KUDU-1896
>             Project: Kudu
>          Issue Type: Bug
>          Components: security
>    Affects Versions: 1.3.0
>            Reporter: Todd Lipcon
>            Assignee: Todd Lipcon
>            Priority: Blocker
>             Fix For: 1.3.0
>
>
> Currently even if security is enabled, you can use the web UI 
> tracing/rpcz/etc to see current RPC traffic, including tokens returned from 
> ConnectToMaster RPCs, etc. We need to enable redaction for the stringified 
> PBs in the traces, and probably offer the ability to disable web UI pages 
> entirely.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Reply via email to