YARN-9727: Allowed Origin pattern is discouraged if regex contains *. Contributed by Zoltan Siegl
This commit is contained in:
parent
a92b7a5491
commit
df30d8ea09
@ -197,7 +197,7 @@ private void initializeAllowedOrigins(FilterConfig filterConfig) {
|
||||
LOG.info("Allowed Origins: " + StringUtils.join(allowedOrigins, ','));
|
||||
LOG.info("Allow All Origins: " + allowAllOrigins);
|
||||
List<String> discouragedAllowedOrigins = allowedOrigins.stream()
|
||||
.filter(s -> s.length() > 1 && s.contains("*"))
|
||||
.filter(s -> s.length() > 1 && s.contains("*") && !(s.startsWith(ALLOWED_ORIGINS_REGEX_PREFIX)))
|
||||
.collect(Collectors.toList());
|
||||
for (String discouragedAllowedOrigin : discouragedAllowedOrigins) {
|
||||
LOG.warn("Allowed Origin pattern '" + discouragedAllowedOrigin + "' is discouraged, use the 'regex:' prefix and use a Java regular expression instead.");
|
||||
|
Loading…
Reference in New Issue
Block a user