Re: stats admin: regression in 1.5-dev9 and potential security issue

2012-05-11 Thread Cyril Bonté
Hi Willy, Le 10/05/2012 23:49, Willy Tarreau a écrit : (...) I've pushed the fixes and will probably issue -dev10 this week-end if nothing else needs to delay it. Great ! I've installed the last snapshot and currently everything works well. And the good news for me is that tracking the

Re: stats admin: regression in 1.5-dev9 and potential security issue

2012-05-11 Thread Willy Tarreau
Hi Cyril, On Fri, May 11, 2012 at 09:01:50AM +0200, Cyril Bonté wrote: Hi Willy, Le 10/05/2012 23:49, Willy Tarreau a écrit : (...) I've pushed the fixes and will probably issue -dev10 this week-end if nothing else needs to delay it. Great ! I've installed the last snapshot and

Re: stats admin: regression in 1.5-dev9 and potential security issue

2012-05-10 Thread Willy Tarreau
Hi Cyril, On Wed, May 09, 2012 at 08:33:05PM +0200, Cyril Bonté wrote: Hi Willy, Just after your announce, I've upgraded from haproxy 1.4.20 to 1.5-dev9 on a test machine. Today, I suddenly realize that the stats web page allows to disable/enable servers (and the result message is a bit

Re: stats admin: regression in 1.5-dev9 and potential security issue

2012-05-10 Thread Willy Tarreau
On Thu, May 10, 2012 at 12:15:14AM +0200, Cyril Bonté wrote: Hi again, I couldn't find time to find a fix, but i could isolate the behaviour change...and also discovered other issues :-( See below. Le 09/05/2012 20:33, Cyril Bonté a écrit : Hi Willy, Just after your announce, I've

Re: stats admin: regression in 1.5-dev9 and potential security issue

2012-05-10 Thread Willy Tarreau
Hi Cyril, On Thu, May 10, 2012 at 12:15:14AM +0200, Cyril Bonté wrote: Some ACLs : acl AUTH http_auth(stats-auth) acl AUTH_ADMIN http_auth_group(stats-auth) admin http_auth_group is the culprit : with the new ACL management, haproxy fully ignores the group(s) provided.

stats admin: regression in 1.5-dev9 and potential security issue

2012-05-09 Thread Cyril Bonté
Hi Willy, Just after your announce, I've upgraded from haproxy 1.4.20 to 1.5-dev9 on a test machine. Today, I suddenly realize that the stats web page allows to disable/enable servers (and the result message is a bit weird, as the action is applied but it gives an Unexpected result message).

Re: stats admin: regression in 1.5-dev9 and potential security issue

2012-05-09 Thread Cyril Bonté
Hi again, I couldn't find time to find a fix, but i could isolate the behaviour change...and also discovered other issues :-( See below. Le 09/05/2012 20:33, Cyril Bonté a écrit : Hi Willy, Just after your announce, I've upgraded from haproxy 1.4.20 to 1.5-dev9 on a test machine. Today, I