Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id EAC1F200D0B for ; Wed, 27 Sep 2017 18:38:09 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id E92D61609CA; Wed, 27 Sep 2017 16:38:09 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 3A6141609C1 for ; Wed, 27 Sep 2017 18:38:09 +0200 (CEST) Received: (qmail 84040 invoked by uid 500); 27 Sep 2017 16:38:03 -0000 Mailing-List: contact common-issues-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list common-issues@hadoop.apache.org Received: (qmail 84027 invoked by uid 99); 27 Sep 2017 16:38:03 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 27 Sep 2017 16:38:03 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id E3AAD180DA2 for ; Wed, 27 Sep 2017 16:38:02 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: -100.002 X-Spam-Level: X-Spam-Status: No, score=-100.002 tagged_above=-999 required=6.31 tests=[RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, USER_IN_WHITELIST=-100] autolearn=disabled Received: from mx1-lw-eu.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id qPa4vHXUUnnO for ; Wed, 27 Sep 2017 16:38:02 +0000 (UTC) Received: from mailrelay1-us-west.apache.org (mailrelay1-us-west.apache.org [209.188.14.139]) by mx1-lw-eu.apache.org (ASF Mail Server at mx1-lw-eu.apache.org) with ESMTP id D047461063 for ; Wed, 27 Sep 2017 16:38:01 +0000 (UTC) Received: from jira-lw-us.apache.org (unknown [207.244.88.139]) by mailrelay1-us-west.apache.org (ASF Mail Server at mailrelay1-us-west.apache.org) with ESMTP id C99C0E03EE for ; Wed, 27 Sep 2017 16:38:00 +0000 (UTC) Received: from jira-lw-us.apache.org (localhost [127.0.0.1]) by jira-lw-us.apache.org (ASF Mail Server at jira-lw-us.apache.org) with ESMTP id 18E662428E for ; Wed, 27 Sep 2017 16:38:00 +0000 (UTC) Date: Wed, 27 Sep 2017 16:38:00 +0000 (UTC) From: "Johannes Alberti (JIRA)" To: common-issues@hadoop.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Updated] (HADOOP-14908) CrossOriginFilter should trigger regex on more input MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 archived-at: Wed, 27 Sep 2017 16:38:10 -0000 [ https://issues.apache.org/jira/browse/HADOOP-14908?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Johannes Alberti updated HADOOP-14908: -------------------------------------- Status: In Progress (was: Patch Available) > CrossOriginFilter should trigger regex on more input > ---------------------------------------------------- > > Key: HADOOP-14908 > URL: https://issues.apache.org/jira/browse/HADOOP-14908 > Project: Hadoop Common > Issue Type: Improvement > Components: common, security > Affects Versions: 3.0.0-beta1 > Reporter: Allen Wittenauer > Assignee: Johannes Alberti > > Currently, CrossOriginFilter.java limits regex matching only if there is an asterisk (\*) in the config. > {code} > if (allowedOrigin.contains("*")) { > {code} > This means that entries such as: > {code} > http?://foo.example.com > https://[a-z][0-9].example.com > {code} > ... and other patterns that succinctly limit the input space need to either be fully expanded or dramatically have their space increased by using an asterisk in order to pass through the filter. -- This message was sent by Atlassian JIRA (v6.4.14#64029) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org For additional commands, e-mail: common-issues-help@hadoop.apache.org