----------------------------------------------------------- This is an automatically generated e-mail. To reply, visit: https://reviews.apache.org/r/58096/ -----------------------------------------------------------
(Updated May 10, 2017, 9:46 p.m.) Review request for mesos, Adam B, Alexander Rojas, and Benjamin Mahler. Changes ------- address comments. Bugs: MESOS-7260 https://issues.apache.org/jira/browse/MESOS-7260 Repository: mesos Description ------- While /roles displays a list of frameworksIds that register with a role, it did NOT filter them based on VIEW_FRAMEWORK ACL, which impose a security risk. This patch fixed this issue by taking a frameworksApprover in `Master::Http::roles()` which is used to filter framework IDs. Diffs (updated) ----- src/master/http.cpp e2590a17044ac019b24a24629428d4ec8adc0c31 Diff: https://reviews.apache.org/r/58096/diff/6/ Changes: https://reviews.apache.org/r/58096/diff/5-6/ Testing ------- see next patch in the chain. Thanks, Jay Guo