Skip to content

Conversation

@djoelz
Copy link

@djoelz djoelz commented Aug 16, 2015

Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server.
Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.

joelz added 2 commits August 16, 2015 03:08
… issue requests from a site other than the zeppelin server.

Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.
… issue requests from a site other than the zeppelin server.

Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.
@djoelz djoelz changed the title Fixing insecure CORS filter settings Zeppelin enables CORS (Cross-Origin Request Sharing) by default with insecure settings (Access-Control-Allow-Origin: *) Aug 16, 2015
@Leemoonsoo
Copy link
Member

Thanks @djoelz. LGTM

@djoelz
Copy link
Author

djoelz commented Aug 18, 2015

Once @jonbuffington change goes thru I will update this to use that as well.

@djoelz
Copy link
Author

djoelz commented Aug 19, 2015

Can we merge this? I have the fix for the configuration issues done but this needs to go thru first, unless we want it here as a bigger PR.
Thanks!

@asfgit asfgit closed this in 4818f07 Aug 20, 2015
@Leemoonsoo Leemoonsoo mentioned this pull request Aug 20, 2015
Leemoonsoo pushed a commit to Leemoonsoo/zeppelin that referenced this pull request Sep 17, 2015
…insecure settings (Access-Control-Allow-Origin: *)

Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server.
Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework).
Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.

Author: joelz <djoelz@gmail.com>
Author: djoelz <joelz@microsoft.com>

Closes apache#216 from djoelz/master and squashes the following commits:

a00adc2 [djoelz] Merge pull request #1 from apache/master
df324de [joelz] Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server. Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework). Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.
cecbab8 [joelz] Fixing cross origin bug for rest calls that allow a malicious user to issue requests from a site other than the zeppelin server. Adding unit tests and a dependency to mockito to the server project (please comment if that is ok or if there is another preferred mocking framework). Also upgrading the servelet version from 2.5 to 3.0 as this also fixes a security vulnerability with respect to httonly cookies.

(cherry picked from commit 4818f07)
Signed-off-by: Lee moon soo <moon@apache.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants