Return-Path: X-Original-To: apmail-hadoop-mapreduce-issues-archive@minotaur.apache.org Delivered-To: apmail-hadoop-mapreduce-issues-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id BDEEA9EE4 for ; Fri, 21 Oct 2011 08:33:00 +0000 (UTC) Received: (qmail 23896 invoked by uid 500); 21 Oct 2011 08:33:00 -0000 Delivered-To: apmail-hadoop-mapreduce-issues-archive@hadoop.apache.org Received: (qmail 23651 invoked by uid 500); 21 Oct 2011 08:32:55 -0000 Mailing-List: contact mapreduce-issues-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: mapreduce-issues@hadoop.apache.org Delivered-To: mailing list mapreduce-issues@hadoop.apache.org Received: (qmail 23624 invoked by uid 99); 21 Oct 2011 08:32:53 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 21 Oct 2011 08:32:53 +0000 X-ASF-Spam-Status: No, hits=-2000.5 required=5.0 tests=ALL_TRUSTED,RP_MATCHES_RCVD X-Spam-Check-By: apache.org Received: from [140.211.11.116] (HELO hel.zones.apache.org) (140.211.11.116) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 21 Oct 2011 08:32:51 +0000 Received: from hel.zones.apache.org (hel.zones.apache.org [140.211.11.116]) by hel.zones.apache.org (Postfix) with ESMTP id 71D7E3149C8 for ; Fri, 21 Oct 2011 08:30:32 +0000 (UTC) Date: Fri, 21 Oct 2011 08:30:32 +0000 (UTC) From: "Luke Lu (Commented) (JIRA)" To: mapreduce-issues@hadoop.apache.org Message-ID: <1537339136.151.1319185832467.JavaMail.tomcat@hel.zones.apache.org> In-Reply-To: <609327193.15684.1319124790850.JavaMail.tomcat@hel.zones.apache.org> Subject: [jira] [Commented] (MAPREDUCE-3231) Improve Application Master And Job History UI Security MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/MAPREDUCE-3231?page=3Dcom.atlas= sian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=3D= 13132511#comment-13132511 ]=20 Luke Lu commented on MAPREDUCE-3231: ------------------------------------ If I understand your proposal correctly, you're trying to invent a less pow= erful but "more secure" alternative language to html/js/css for a trusted w= eb server (essentially a proxy) to assemble html/js/css for end users. Besi= des the complexity of the approach (e.g., you'll have to at least invent a = robust stream based json parser that can handle adversarial long name and v= alues, which doesn't exist yet (with a compatible open source license anywa= y), which you seem to underestimate, it's a non-starter for deployments tha= t do not require such security and/or have a commercial transparent proxy t= hat can handle the webapp security just fine. A fundamental requirement for= hadoop security is that it must be optional and pluggable. Your proposal r= equires people to rewrite their webapps in your extremely restrictive way. = It's fundamentally wrong on so many levels. The web proxy design (in MAPRED= UCE-2858) in conjunction with code whitelisting can give user complete free= dom in AM UI design, while adequately ensure security when it's needed. I'm strongly -1 on any proposal that impose mandatory significant restricti= on on people's freedom to create their own web UI in the cloud/cluster/grid= . =20 > Improve Application Master And Job History UI Security > ------------------------------------------------------ > > Key: MAPREDUCE-3231 > URL: https://issues.apache.org/jira/browse/MAPREDUCE-3231 > Project: Hadoop Map/Reduce > Issue Type: Improvement > Components: mrv2 > Affects Versions: 0.23.0 > Reporter: Robert Joseph Evans > Assignee: Robert Joseph Evans > Attachments: AMWebSecurityProposal.pdf > > > I propose a stripped down JSON based protocol for creating safe user gene= rate web pages. This JIRA is intended first of all as a place for a discus= sion about this proposal, and then if there are no serious objections this = will be an Umbrella JIRA to implement the changes proposed. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrato= rs: https://issues.apache.org/jira/secure/ContactAdministrators!default.jsp= a For more information on JIRA, see: http://www.atlassian.com/software/jira