Skip to content

Restrict full web console URI to admins role#2074

Merged
cshannon merged 1 commit into
apache:mainfrom
jbonofre:webconsole-admin-restriction
Jun 8, 2026
Merged

Restrict full web console URI to admins role#2074
cshannon merged 1 commit into
apache:mainfrom
jbonofre:webconsole-admin-restriction

Conversation

@jbonofre
Copy link
Copy Markdown
Member

@jbonofre jbonofre commented Jun 4, 2026

Restrict the full web console URI (/admin/*) to the admins role instead of only *.action endpoints, add comments documenting each constraint mapping, and remove a duplicated pair of Referrer-Policy and Permissions-Policy rewrite rules in assembly/src/release/conf/jetty.xml.

Change the admin security constraint mapping from *.action to /admin/*
so the entire web console (including read-only pages) requires the
admins role, not just action endpoints. Add comments to each constraint
mapping explaining its scope, and remove duplicate Referrer-Policy and
Permissions-Policy rewrite rules left over from earlier edits.
@cshannon cshannon merged commit 085efea into apache:main Jun 8, 2026
9 of 10 checks passed
cshannon added a commit that referenced this pull request Jun 8, 2026
Change the admin security constraint mapping from *.action to /admin/*
so the entire web console (including read-only pages) requires the
admins role, not just action endpoints. Add comments to each constraint
mapping explaining its scope, and remove duplicate Referrer-Policy and
Permissions-Policy rewrite rules left over from earlier edits.

(cherry picked from commit 085efea)

Co-authored-by: JB Onofré <jbonofre@apache.org>
cshannon added a commit that referenced this pull request Jun 8, 2026
Change the admin security constraint mapping from *.action to /admin/*
so the entire web console (including read-only pages) requires the
admins role, not just action endpoints. Add comments to each constraint
mapping explaining its scope, and remove duplicate Referrer-Policy and
Permissions-Policy rewrite rules left over from earlier edits.

(cherry picked from commit 085efea)

Co-authored-by: JB Onofré <jbonofre@apache.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants