[jira] [Created] (IGNITE-9472) REST API has no permission checks for cluster activation/deactivation

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Created] (IGNITE-9472) REST API has no permission checks for cluster activation/deactivation

Anton Vinogradov (Jira)
Ivan Bessonov created IGNITE-9472:
-------------------------------------

             Summary: REST API has no permission checks for cluster activation/deactivation
                 Key: IGNITE-9472
                 URL: https://issues.apache.org/jira/browse/IGNITE-9472
             Project: Ignite
          Issue Type: Bug
            Reporter: Ivan Bessonov
            Assignee: Ivan Bessonov


ADMIN_OPS permission should be required for CLUSTER_ACTIVE / CLUSTER_INACTIVE commands. This has to be done in GridRestProcessor.authorize method.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)