[jboss-jira] [JBoss JIRA] (AS7-2586) Block all HTTP access to management interface if there is a realm defined and it does not have users defined.

Darran Lofthouse (Resolved) (JIRA) jira-events at lists.jboss.org
Tue Nov 22 15:51:40 EST 2011


     [ https://issues.jboss.org/browse/AS7-2586?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Darran Lofthouse resolved AS7-2586.
-----------------------------------

    Resolution: Done


https://github.com/jbossas/jboss-as/commit/78fd5ef4d42ac1fe9e6d8b64a5bea9814b0b5ead
https://github.com/jbossas/jboss-as/commit/23a0fd01925b8c820978c9ea6c6ec643adb1a225
                
> Block all HTTP access to management interface if there is a realm defined and it does not have users defined.
> -------------------------------------------------------------------------------------------------------------
>
>                 Key: AS7-2586
>                 URL: https://issues.jboss.org/browse/AS7-2586
>             Project: Application Server 7
>          Issue Type: Task
>          Components: Domain Management, Security
>            Reporter: Darran Lofthouse
>            Assignee: Darran Lofthouse
>            Priority: Blocker
>             Fix For: 7.1.0.Beta1
>
>
> Will add some form of filter to the HTTP interface to redirect to a descriptive error page when there is no user defined.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.jboss.org/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


More information about the jboss-jira mailing list