[jboss-jira] [JBoss JIRA] (AS7-2429) Implement a User Agent and Remote Address Filter for the HTTP Management Interface

Jean-Frederic Clere (JIRA) jira-events at lists.jboss.org
Tue Jan 22 02:43:22 EST 2013


    [ https://issues.jboss.org/browse/AS7-2429?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12749337#comment-12749337 ] 

Jean-Frederic Clere commented on AS7-2429:
------------------------------------------

Note that the jbossweb branch still have the logic in the connector but a filter or a valve is probably the cleanest way to go because it could be done by webapp.
                
> Implement a User Agent and Remote Address Filter for the HTTP Management Interface
> ----------------------------------------------------------------------------------
>
>                 Key: AS7-2429
>                 URL: https://issues.jboss.org/browse/AS7-2429
>             Project: Application Server 7
>          Issue Type: Feature Request
>          Components: Domain Management, Security
>            Reporter: Darran Lofthouse
>            Assignee: Tommy Tynjä
>             Fix For: Open To Community
>
>
> The HTTP Management interface provides access to manage the domain model, this interface is partly dependent on the protection supplied by an end users web browser.
> This feature request is to optionally filter inbound requests based on a configurable list of supported user agents and or remote addresses - this will mean buggy browser versions can be excluded and remote clients restricted.
> Anyone interested in contributing please feel free to ping darranl in #jboss-as7.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira



More information about the jboss-jira mailing list