[jboss-jira] [JBoss JIRA] (WFLY-705) Implement a User Agent and Remote Address Filter for the HTTP Management Interface

Darran Lofthouse (JIRA) issues at jboss.org
Fri Jan 24 05:32:28 EST 2014


    [ https://issues.jboss.org/browse/WFLY-705?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12938498#comment-12938498 ] 

Darran Lofthouse commented on WFLY-705:
---------------------------------------

Yes following on from a few discussions we have had recently we need to expand quite a bit on the configuration of the management interfaces, this is one aspect, cross origin resource sharing is another, enhancements to security is another, there are a few others as well but essentially yes it all should happen under WFLY-2635.
                
> Implement a User Agent and Remote Address Filter for the HTTP Management Interface
> ----------------------------------------------------------------------------------
>
>                 Key: WFLY-705
>                 URL: https://issues.jboss.org/browse/WFLY-705
>             Project: WildFly
>          Issue Type: Feature Request
>      Security Level: Public(Everyone can see) 
>          Components: Domain Management, Security
>            Reporter: Darran Lofthouse
>            Assignee: Andre Dietisheim
>             Fix For: 8.0.0.CR1
>
>
> The HTTP Management interface provides access to manage the domain model, this interface is partly dependent on the protection supplied by an end users web browser.
> This feature request is to optionally filter inbound requests based on a configurable list of supported user agents and or remote addresses - this will mean buggy browser versions can be excluded and remote clients restricted.
> Anyone interested in contributing please feel free to ping darranl in #jboss-as7.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the jboss-jira mailing list