mesos-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Vinod Kone (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (MESOS-5918) Replace jsonp with a more secure alternative
Date Tue, 23 Jan 2018 18:43:00 GMT

     [ https://issues.apache.org/jira/browse/MESOS-5918?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Vinod Kone updated MESOS-5918:
------------------------------
    Component/s: json api

> Replace jsonp with a more secure alternative
> --------------------------------------------
>
>                 Key: MESOS-5918
>                 URL: https://issues.apache.org/jira/browse/MESOS-5918
>             Project: Mesos
>          Issue Type: Improvement
>          Components: json api, webui
>            Reporter: Yan Xu
>            Priority: Major
>              Labels: security
>
> We currently use the {{jsonp}} technique to bypass CORS check. This practice has many
security concerns (see discussions on MESOS-5911) so we should replace it with a better alternative.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Mime
View raw message