Github user andrewor14 commented on the pull request:

    https://github.com/apache/spark/pull/9321#issuecomment-167644002
  
    > On the other hand, I cannot see serious issues by allowing user to 
potentially read any files under workerDir, it will display the bytecode if 
reading a jar file but I think the user already have full control access to all 
the files under workerDir, except for maybe other spark app's jar files.
    
    What if I have some plain text secret (e.g. private key) in some file? 
Anyone with access to the UI will be able to read it.


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at [email protected] or file a JIRA ticket
with INFRA.
---

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to