[ https://issues.apache.org/jira/browse/SOLR-13942?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16977435#comment-16977435 ]
Noble Paul edited comment on SOLR-13942 at 11/19/19 12:26 PM: -------------------------------------------------------------- However, it's A very useful API. We can't let users access zk directly. It's a security hole. This is safe. This information is already exposed via another API, so, it's not a new security vulnerability. That API is used by admin gui. Is not even protected. This is I don't agree with your suggestion that everything should go through the dev list. All discussions on JIRA go to mailing list. You get mails for each ticket/comment. was (Author: noble.paul): However, it's A very useful API. We can't let users access zk directly. It's a security hole. This is safe. This information is already exposed via another API, so, it's not a new security vulnerability. That API is used by admin gui. Is not even protected. This is > /api/cluster/zk/* to fetch raw ZK data > -------------------------------------- > > Key: SOLR-13942 > URL: https://issues.apache.org/jira/browse/SOLR-13942 > Project: Solr > Issue Type: Bug > Security Level: Public(Default Security Level. Issues are Public) > Reporter: Noble Paul > Priority: Major > > If the requested path is a node with children show the list of child nodes > and their meta data -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org