dinky icon indicating copy to clipboard operation
dinky copied to clipboard

[Optimization][Devops] Dinky Devops FlinkWebUI can access directly And it may cause security issues

Open HejiaHo opened this issue 2 years ago • 1 comments

Search before asking

  • [X] I had searched in the issues and found no similar optimization requirement.

Description

Dinky proxy Flink dashboard, and it can directly access by http://[dinky_host]:[dinky_port]/api/flink/localhost:8082/#/, don't need Dinky auth. Flink dashboard can submit jar,and it can cause security issues. I wish access Devops FlinkWebUI need Diny auth OR disable FlinkWebUI by setting property file.

Are you willing to submit a PR?

  • [ ] Yes I am willing to submit a PR!

Code of Conduct

HejiaHo avatar Apr 30 '24 03:04 HejiaHo

Hello @HejiaHo, this issue is about web, so I assign it to @Zzm0809. If you have any questions, you can comment and reply.

你好 @HejiaHo, 这个 issue 是关于 web 的,所以我把它分配给了 @Zzm0809。如有任何问题,可以评论回复。

github-actions[bot] avatar Apr 30 '24 03:04 github-actions[bot]

目前在 Dinky 内运维中心访问跳转时需要有 dinky 登录后的 token, 否则无法访问

Zzm0809 avatar Apr 30 '24 09:04 Zzm0809

禁用jar 提交自行通过flink 配置文件控制, dinky 不介入这个

Zzm0809 avatar Apr 30 '24 09:04 Zzm0809

目前在 Dinky 内运维中心访问跳转时需要有 dinky 登录后的 token, 否则无法访问

http://[dinky_host]:[dinky_port]/api/flink/localhost:8082/#/ 经测试,通过该方式是可以直接访问的,不需要任何认证。无痕模式或者换个浏览器都可以访问到。

HejiaHo avatar Apr 30 '24 17:04 HejiaHo

目前在 Dinky 内运维中心访问跳转时需要有 dinky 登录后的 token, 否则无法访问

http://[dinky_host]:[dinky_port]/api/flink/localhost:8082/#/ 经测试,通过该方式是可以直接访问的,不需要任何认证。无痕模式或者换个浏览器都可以访问到。

1.0.2 has fixd

gaoyan1998 avatar May 07 '24 01:05 gaoyan1998