nick-boss-tech commented on code in PR #5016:
URL: https://github.com/apache/solr/pull/5016#discussion_r4196728403


##########
solr/solr-ref-guide/modules/upgrade-notes/pages/major-changes-in-solr-11.adoc:
##########
@@ -41,3 +41,11 @@ bin/solr start -Dsolr.node.roles=data:on,overseer:preferred
 
 A node started this way asks the Overseer to re-run its node prioritization, 
so a preferred node takes over without waiting for the current Overseer to 
restart.
 Note that node roles are fixed for the lifetime of a node: unlike `ADDROLE`, 
they cannot be changed on a running node.
+
+== Security Changes
+
+=== Core-Scoped Authorization Rules in Standalone Mode
+
+In standalone mode, authorization permissions that set `collection` to a core 
name were never applied, so requests to that core were matched only against the 
permissions that apply to all collections.

Review Comment:
   🤖 *AI text below* 🤖 *(posted on behalf of Nick Shanin)*
   
   Moved rather than dropped: the note now sits as a new Solr 10.2 security 
section in major-changes-in-solr-10.adoc, and the Solr 11 addition is removed. 
I kept a note because this changes security behavior for anyone relying on the 
old ignoring. Happy to drop it entirely if you prefer.



##########
changelog/unreleased/SOLR-13097.yml:
##########
@@ -0,0 +1,7 @@
+title: Authorization permissions scoped to a core with the collection field 
are now enforced in standalone mode, where they were silently ignored
+type: changed

Review Comment:
   🤖 *AI text below* 🤖 *(posted on behalf of Nick Shanin)*
   
   Reframed as fixed: the changelog now reads type fixed with the title 
"Core-scoped authorization permissions were not applied in standalone mode". 
The ticket is filed as a bug, and the security docs present the plugins as 
working in standalone with no carve-out for scoped permissions, so the fix 
framing fits. I also added the sentence you suggested to the RBAP page: the 
collection parameter description now says that in standalone mode the value can 
be the name of a core and applies to requests served by that core.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to