nick-boss-tech opened a new pull request, #5016:
URL: https://github.com/apache/solr/pull/5016

   🤖 *AI text below* 🤖 *(posted on behalf of Nick Shanin)*
   
   https://issues.apache.org/jira/browse/SOLR-13097
   
   Authorization rules scoped to a collection could never match in standalone 
mode. `HttpSolrCall` built the authorization context's collection list only for 
ZooKeeper-aware (cloud) deployments, so in standalone mode the list was empty 
and a rule scoped through the "collection" field had nothing to match against, 
even when the admin had configured it for the core being served.
   
   In standalone mode the list now contains the serving core's name, so 
core-scoped rules match the core the request actually hits. Cloud behavior is 
unchanged. This gives standalone requests a one-element authorization context; 
it does not change which permissions exist or how rules are evaluated. Related 
authorization scoping discussion: SOLR-15304.
   
   The new `CoreScopedAuthStandaloneTest` verifies that a core-scoped rule 
allows the configured role in standalone mode.
   
   Validation on the final tree: Error Prone compile clean, 
`CoreScopedAuthStandaloneTest` passes, `tidy` applied (one javadoc reflow in 
the new test, committed), `:solr:core:check -x test` green; test and check 
re-run on the exact committed tree.
   
   Changelog: `changelog/unreleased/SOLR-13097.yml` (type fixed).
   
   ### AI assistance
   AI agents assisted with research, implementation, review, and drafting. Nick 
Shanin directed the work and takes responsibility for this contribution.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to