[ 
https://issues.apache.org/jira/browse/SOLR-16327?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17577542#comment-17577542
 ] 

Shawn Heisey edited comment on SOLR-16327 at 8/9/22 5:31 PM:
-------------------------------------------------------------

{quote}Note that the Ping request needs the new "health" permission.
{quote}
In my case, I don't have a security.json at all.  No security configured.  I am 
accessing the UI with https (actually HTTP/3), but it is haproxy providing 
that.  Solr/Jetty is not encrypted.
{quote}So, are you saying this happens in Solr 9, but not 8?
{quote}
Yes, that is exactly what I found.  On 8.11.1 I added the ping handler to the 
config on a core created from _default, but I confess that I did not copy the 
entire solrconfig.xml from the 9.1.0-SNAPSHOT server.  I will need to do some 
more controlled testing.

I haven't tried cloud mode.


was (Author: elyograg):
{quote}Note that the Ping request needs the new "health" permission.
{quote}
In my case, I don't have a security.json at all.  No security configured.  I am 
accessing the UI with https (actually HTTP/3), but it is haproxy providing 
that.  Solr/Jetty is not encrypted.
{quote}So, are you saying this happens in Solr 9, but not 8?
{quote}
Yes, that is exactly what I found.  I added the ping handler to the config on a 
core created from _default, but I confess that I did not copy the entire 
solrconfig.xml from the 9.1.0-SNAPSHOT server.  I will need to do some more 
controlled testing.

I haven't tried cloud mode.

> Admin UI reports permission error if the request it made results in ANY 
> exception
> ---------------------------------------------------------------------------------
>
>                 Key: SOLR-16327
>                 URL: https://issues.apache.org/jira/browse/SOLR-16327
>             Project: Solr
>          Issue Type: Bug
>      Security Level: Public(Default Security Level. Issues are Public) 
>          Components: Admin UI
>    Affects Versions: main (10.0)
>            Reporter: Shawn Heisey
>            Priority: Minor
>         Attachments: image-2022-08-06-15-36-24-158.png, screenshot-1.png, 
> solr9_ping_exception.txt
>
>
> A lot of the pages in the UI report permission errors even when the actual 
> problem is some other exception.  For this screenshot, I clicked first on the 
> Overview, and then on Ping ... there was a misconfig in the ping handler 
> where it was not declaring a default field, so the query generated an 
> exception which is attached to the issue.  I did not have a security.json 
> file.
> !image-2022-08-06-15-36-24-158.png|width=389,height=182!
> I also saw this on other things besides Ping when I was clicking around the 
> admin UI during a solr service restart.  The version info showing where the 
> git repo was when I compiled from branch_9x:
> 9.1.0-SNAPSHOT f1510b1f54ea9225df654e3aad0ca7da856c1f72 [snapshot build, 
> details omitted]
>  
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to