[Security] Check if druid.client.https.validateHostnames can be turned of
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- kubernetes, rust
调研方向
从 rust/crd/src/security.rs 第330-336行附近开始,检查 druid.client.https.validateHostnames 和 druid.server.https.validateHostnames 的配置方式。测试受影响的 Druid 部署行为,并确定需要什么配置才能移除不安全的 false 设置。当这些设置不再被强制设为 false 且相关测试通过时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Affected version
nightly
Current and expected behavior
Currently we set druid.client.https.validateHostnames and druid.server.https.validateHostnames to false which imposes a security risk.
We should get rid of it.
Context: https://github.com/stackabletech/druid-operator/blob/d4477a5e8c802bd1059e592c82fd1632a3aef63a/rust/crd/src/security.rs#L330-L336
Possible solution
No idea, needs testing
Additional context
No response
Environment
No response
Would you like to work on fixing this bug?
None
- 主要语言
- Rust
- 星标
- 12
- 派生
- 1
- 平均合并
- 1 天 17 小时
- 30 天内合并 PR
- 10
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
stackabletech/druid-operator 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 35/100
stackabletech/druid-operator#692 ·
-
难度 3/5 1-2 天 新手友好度 45/100
stackabletech/druid-operator#647 ·
-
难度 3/5 1-2 天 新手友好度 30/100
stackabletech/druid-operator#646 ·
-
type/bug
难度 5/5 一周以上 新手友好度 20/100
stackabletech/druid-operator#606 · 3 条评论 ·
-
Server failing to create PoolableConnectionFactory. Failing with SCRAM-based authentication error. 未关闭type/bug
难度 4/5 3-5 天 新手友好度 25/100
stackabletech/druid-operator#605 ·
查看 stackabletech/druid-operator 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 85/100
-
难度 2/5 1-3 小时 新手友好度 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
-
bug team:backend track:services-maintenance
难度 2/5 1-3 小时 新手友好度 78/100
cowprotocol/services#4950 ·
-
bug
难度 2/5 1-3 小时 新手友好度 68/100
gitbutlerapp/gitbutler#15998 · 1 条评论 ·