Skip to content

HBASE-26789 Automatically add default security headers to http/rest if SSL enabled - #4128

Merged
meszibalu merged 1 commit into
apache:masterfrom
anmolnar:HBASE-23303_addendum
Mar 2, 2022
Merged

HBASE-26789 Automatically add default security headers to http/rest if SSL enabled#4128
meszibalu merged 1 commit into
apache:masterfrom
anmolnar:HBASE-23303_addendum

Conversation

@anmolnar

Copy link
Copy Markdown
Contributor

Originally it was implemented with empty default values, but it actually makes sense to automatically enabled them if SSL is turned on. It's still possible to override via config, but the default behaviour is more secure.

@Apache-HBase

Copy link
Copy Markdown

🎊 +1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 40sDocker mode activated.
-0 ⚠️yetus0m 2sUnprocessed flag(s): --brief-report-file --spotbugs-strict-precheck --whitespace-eol-ignore-list --whitespace-tabs-ignore-list --quick-hadoopcheck
_ Prechecks _
_ master Compile Tests _
+0 🆗mvndep0m 36sMaven dependency ordering for branch
+1 💚mvninstall3m 3smaster passed
+1 💚compile0m 27smaster passed
+1 💚shadedjars5m 4sbranch has no errors when building our shaded downstream artifacts.
+1 💚javadoc0m 23smaster passed
_ Patch Compile Tests _
+0 🆗mvndep0m 10sMaven dependency ordering for patch
+1 💚mvninstall2m 48sthe patch passed
+1 💚compile0m 28sthe patch passed
+1 💚javac0m 28sthe patch passed
+1 💚shadedjars5m 0spatch has no errors when building our shaded downstream artifacts.
+1 💚javadoc0m 21sthe patch passed
_ Other Tests _
+1 💚unit0m 47shbase-http in the patch passed.
+1 💚unit4m 51shbase-rest in the patch passed.
25m 46s
SubsystemReport/Notes
DockerClientAPI=1.41 ServerAPI=1.41 base: https://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/artifact/yetus-jdk11-hadoop3-check/output/Dockerfile
GITHUB PR#4128
Optional Testsjavac javadoc unit shadedjars compile
unameLinux 9cbd68ee439f 5.4.0-1025-aws #25~18.04.1-Ubuntu SMP Fri Sep 11 12:03:04 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
Personalitydev-support/hbase-personality.sh
git revisionmaster / cd45cad
Default JavaAdoptOpenJDK-11.0.10+9
Test Resultshttps://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/testReport/
Max. process+thread count1007 (vs. ulimit of 30000)
modulesC: hbase-http hbase-rest U: .
Console outputhttps://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/console
versionsgit=2.17.1 maven=3.6.3
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@Apache-HBase

Copy link
Copy Markdown

🎊 +1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 42sDocker mode activated.
_ Prechecks _
+1 💚dupname0m 0sNo case conflicting files found.
+1 💚hbaseanti0m 0sPatch does not have any anti-patterns.
+1 💚@author0m 0sThe patch does not contain any @author tags.
_ master Compile Tests _
+0 🆗mvndep0m 13sMaven dependency ordering for branch
+1 💚mvninstall2m 36smaster passed
+1 💚compile0m 40smaster passed
+1 💚checkstyle0m 15smaster passed
+1 💚spotbugs0m 43smaster passed
_ Patch Compile Tests _
+0 🆗mvndep0m 10sMaven dependency ordering for patch
+1 💚mvninstall2m 17sthe patch passed
+1 💚compile0m 38sthe patch passed
+1 💚javac0m 38sthe patch passed
-0 ⚠️checkstyle0m 7shbase-http: The patch generated 1 new + 7 unchanged - 0 fixed = 8 total (was 7)
+1 💚checkstyle0m 7shbase-rest: The patch generated 0 new + 6 unchanged - 1 fixed = 6 total (was 7)
+1 💚whitespace0m 0sThe patch has no whitespace issues.
+1 💚hadoopcheck11m 18sPatch does not cause any errors with Hadoop 3.1.2 3.2.2 3.3.1.
+1 💚spotbugs0m 52sthe patch passed
_ Other Tests _
+1 💚asflicense0m 14sThe patch does not generate ASF License warnings.
25m 55s
SubsystemReport/Notes
DockerClientAPI=1.41 ServerAPI=1.41 base: https://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/artifact/yetus-general-check/output/Dockerfile
GITHUB PR#4128
Optional Testsdupname asflicense javac spotbugs hadoopcheck hbaseanti checkstyle compile
unameLinux e0a37bfcce45 5.4.0-1025-aws #25~18.04.1-Ubuntu SMP Fri Sep 11 12:03:04 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
Personalitydev-support/hbase-personality.sh
git revisionmaster / cd45cad
Default JavaAdoptOpenJDK-1.8.0_282-b08
checkstylehttps://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/artifact/yetus-general-check/output/diff-checkstyle-hbase-http.txt
Max. process+thread count60 (vs. ulimit of 30000)
modulesC: hbase-http hbase-rest U: .
Console outputhttps://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/console
versionsgit=2.17.1 maven=3.6.3 spotbugs=4.2.2
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@Apache-HBase

Copy link
Copy Markdown

🎊 +1 overall

VoteSubsystemRuntimeComment
+0 🆗reexec0m 56sDocker mode activated.
-0 ⚠️yetus0m 2sUnprocessed flag(s): --brief-report-file --spotbugs-strict-precheck --whitespace-eol-ignore-list --whitespace-tabs-ignore-list --quick-hadoopcheck
_ Prechecks _
_ master Compile Tests _
+0 🆗mvndep0m 13sMaven dependency ordering for branch
+1 💚mvninstall3m 5smaster passed
+1 💚compile0m 30smaster passed
+1 💚shadedjars5m 39sbranch has no errors when building our shaded downstream artifacts.
+1 💚javadoc0m 28smaster passed
_ Patch Compile Tests _
+0 🆗mvndep0m 15sMaven dependency ordering for patch
+1 💚mvninstall3m 0sthe patch passed
+1 💚compile0m 32sthe patch passed
+1 💚javac0m 32sthe patch passed
+1 💚shadedjars5m 34spatch has no errors when building our shaded downstream artifacts.
+1 💚javadoc0m 24sthe patch passed
_ Other Tests _
+1 💚unit0m 49shbase-http in the patch passed.
+1 💚unit6m 0shbase-rest in the patch passed.
28m 41s
SubsystemReport/Notes
DockerClientAPI=1.41 ServerAPI=1.41 base: https://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/artifact/yetus-jdk8-hadoop3-check/output/Dockerfile
GITHUB PR#4128
Optional Testsjavac javadoc unit shadedjars compile
unameLinux 46416da79c83 5.4.0-1025-aws #25~18.04.1-Ubuntu SMP Fri Sep 11 12:03:04 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux
Build toolmaven
Personalitydev-support/hbase-personality.sh
git revisionmaster / cd45cad
Default JavaAdoptOpenJDK-1.8.0_282-b08
Test Resultshttps://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/testReport/
Max. process+thread count949 (vs. ulimit of 30000)
modulesC: hbase-http hbase-rest U: .
Console outputhttps://ci-hbase.apache.org/job/HBase-PreCommit-GitHub-PR/job/PR-4128/1/console
versionsgit=2.17.1 maven=3.6.3
Powered byApache Yetus 0.12.0 https://yetus.apache.org

This message was automatically generated.

@anmolnaranmolnar changed the title HBASE-23303. Add default security headers if SSL is enabledHBASE-23303. Add default security headers if SSL is enabled [ADDENDUM]Feb 23, 2022
@anmolnaranmolnar changed the title HBASE-23303. Add default security headers if SSL is enabled [ADDENDUM]HBASE-26789 Automatically add default security headers to http/rest if SSL enabledMar 2, 2022
@meszibalu
meszibalu merged commit 87f8d9a into apache:masterMar 2, 2022
asfgit pushed a commit that referenced this pull request Mar 2, 2022
Signed-off-by: Balazs Meszaros <meszibalu@apache.org>
asfgit pushed a commit that referenced this pull request Mar 2, 2022
Signed-off-by: Balazs Meszaros <meszibalu@apache.org>
asfgit pushed a commit that referenced this pull request Mar 2, 2022
Signed-off-by: Balazs Meszaros <meszibalu@apache.org>
@anmolnar
anmolnar deleted the HBASE-23303_addendum branch March 3, 2022 13:34
vinayakphegde pushed a commit to vinayakphegde/hbase that referenced this pull request Apr 4, 2024
Signed-off-by: Balazs Meszaros <meszibalu@apache.org>
(cherry picked from commit 1d0d70e)
Change-Id: Ib5f7910b5a38fcdb5506012a36be1772a5d8393d
Apache9 added a commit that referenced this pull request Oct 26, 2024
Apache9 added a commit that referenced this pull request Oct 26, 2024
Apache9 added a commit that referenced this pull request Oct 26, 2024
Apache9 added a commit that referenced this pull request Oct 26, 2024
Apache9 added a commit that referenced this pull request Oct 26, 2024
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@anmolnar@Apache-HBase@meszibalu