[jira] [Created] (IGNITE-7457) Authorization happens on the Client not Server

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Created] (IGNITE-7457) Authorization happens on the Client not Server

Anton Vinogradov (Jira)
Paul Anderson created IGNITE-7457:
-------------------------------------

             Summary: Authorization happens on the Client not Server
                 Key: IGNITE-7457
                 URL: https://issues.apache.org/jira/browse/IGNITE-7457
             Project: Ignite
          Issue Type: Bug
          Components: cache, clients, general
    Affects Versions: 2.3
         Environment: 2.3.0 Gentoo Linux J1.8
            Reporter: Paul Anderson


Whilst writing an Authentication/Authorization plugin I notice that authorisation takes place on the client rather than on the server (new node authentication takes part on the server) this seems a little insecure as the client can easily deploy with a modified (or without the) plugin.

Just an observation...



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)