janhoy commented on code in PR #5016:
URL: https://github.com/apache/solr/pull/5016#discussion_r4200837864


##########
solr/core/src/java/org/apache/solr/servlet/HttpSolrCall.java:
##########
@@ -219,13 +219,19 @@ public List<String> getCollectionsList() {
   /**
    * The collection(s) to authorize this request against. In SolrCloud, when a 
local core serves the
    * request, this is the collection of that core, since that is where the 
request executes;
-   * requests it sends to other collections are authorized by the receiving 
nodes. Otherwise, this
-   * is {@link #getCollectionsList()}. Not null.
+   * requests it sends to other collections are authorized by the receiving 
nodes. In standalone
+   * mode this is the name of the core serving the request, since there are no 
collections.
+   * Otherwise, this is {@link #getCollectionsList()}. Not null.
    */
   public List<String> getAuthorizationCollectionsList() {
-    if (core == null || !cores.isZooKeeperAware()) {
+    if (core == null) {
       return getCollectionsList();
     }
+    if (!cores.isZooKeeperAware()) {
+      // Standalone mode has no collections; authorize against the serving 
core's name so that
+      // core-scoped authorization rules can match.
+      return List.of(core.getCoreDescriptor().getName());

Review Comment:
   I suppose any change in this domain would be a followup, not part of this PR.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to