Skip to content

Zeppelin enables CORS (Cross-Origin Request Sharing) by default with insecure settings (Access-Control-Allow-Origin: *)#216

Closed
djoelz wants to merge 3 commits intoapache:masterfrom
djoelz:master
Closed

Zeppelin enables CORS (Cross-Origin Request Sharing) by default with insecure settings (Access-Control-Allow-Origin: *)#216
djoelz wants to merge 3 commits intoapache:masterfrom
djoelz:master

Conversation

@djoelz
Copy link
Copy Markdown

@djoelz djoelz commented Aug 16, 2015

Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server.
Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.

… issue requests from a site other than the zeppelin server.

Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.
… issue requests from a site other than the zeppelin server.

Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.
@djoelz djoelz changed the title Fixing insecure CORS filter settings Zeppelin enables CORS (Cross-Origin Request Sharing) by default with insecure settings (Access-Control-Allow-Origin: *) Aug 16, 2015
@Leemoonsoo
Copy link
Copy Markdown
Member

Thanks @djoelz. LGTM

@djoelz
Copy link
Copy Markdown
Author

djoelz commented Aug 18, 2015

Once @jonbuffington change goes thru I will update this to use that as well.

@djoelz
Copy link
Copy Markdown
Author

djoelz commented Aug 19, 2015

Can we merge this? I have the fix for the configuration issues done but this needs to go thru first, unless we want it here as a bigger PR.
Thanks!

@asfgit asfgit closed this in 4818f07 Aug 20, 2015
@Leemoonsoo Leemoonsoo mentioned this pull request Aug 20, 2015
Leemoonsoo pushed a commit to Leemoonsoo/zeppelin that referenced this pull request Sep 17, 2015
…insecure settings (Access-Control-Allow-Origin: *)

Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server.
Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.

Author: joelz <[email protected]>
Author: djoelz <[email protected]>

Closes apache#216 from djoelz/master and squashes the following commits:

a00adc2 [djoelz] Merge pull request #1 from apache/master
df324de [joelz] Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server. Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework). Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.
cecbab8 [joelz] Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server. Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework). Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.

(cherry picked from commit 4818f07)
Signed-off-by: Lee moon soo <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants