[
https://issues.apache.org/jira/browse/SOLR-18474?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18119730#comment-18119730
]
ASF subversion and git services commented on SOLR-18474:
--------------------------------------------------------
Commit 281d3ad2a66735283ac9b6866fdf410a21d2414d in solr's branch
refs/heads/branch_10x from David Smiley
[ https://gitbox.apache.org/repos/asf?p=solr.git;h=281d3ad2a66 ]
SOLR-18474: InternalSolrClientCache separate from SolrClientCache (#4934)
Within Solr, a new security-minded subclass of SolrClientCache is used. The
normal one is forbidden. Clients are unaffected.
Cross-collection join now requires SolrCloud.
Co-authored-by: Claude Opus 5 <[email protected]>
(cherry picked from commit 54a46689b1538319ed464a4f0b40720064f341cf)
> Restrict plain SolrClientCache usage within Solr for better security
> --------------------------------------------------------------------
>
> Key: SOLR-18474
> URL: https://issues.apache.org/jira/browse/SOLR-18474
> Project: Solr
> Issue Type: Improvement
> Components: Server, streaming expressions
> Reporter: David Smiley
> Assignee: David Smiley
> Priority: Major
> Labels: pull-request-available
> Time Spent: 40m
> Remaining Estimate: 0h
>
> SolrClientCache creates SolrClient instances, and thus presents security
> risks/concerns. This is more pronounced after SOLR-18130. This issue
> proposes that a Solr server only ever use a new subclass of SCC designed for
> use within the Solr server and that which uses the "allow" URL/ZK controls of
> the solr server. It shall furthermore be restricted to SolrCloud. The
> base/plain SCC shall only be used by clients (outside Solr).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]