[ 
https://issues.apache.org/jira/browse/SOLR-527?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12585573#action_12585573
 ] 

Sean Timm commented on SOLR-527:
--------------------------------

Thanks all for taking a look at this.

The ReadOnlyUpdateProcessorFactory.java is great, Ryan.  I didn't realize that 
update processor factories could be chained.  That is cleaner than my solution.

Hoss, I realize that DOS attacks are still possible, however, my bigger concern 
is someone modifying our index (e.g., injecting a Viagra advert or the like 
into our index).

> An XML commit only request handler
> ----------------------------------
>
>                 Key: SOLR-527
>                 URL: https://issues.apache.org/jira/browse/SOLR-527
>             Project: Solr
>          Issue Type: New Feature
>          Components: update
>    Affects Versions: 1.3
>            Reporter: Sean Timm
>            Priority: Trivial
>         Attachments: ReadOnlyUpdateProcessorFactory.java, 
> ReadOnlyUpdateProcessorFactory.java, SOLR-527.patch
>
>
> This request handler only permits <commit/> messages.  It is provided as one 
> way to prevent adds and deletes on a Solr slave machine that could 
> potentially be accessed by outside parties where a firewall or other access 
> control is either not possible or not desired.

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to