CalvinKirs opened a new pull request, #68659:
URL: https://github.com/apache/doris/pull/68659
### What problem does this PR solve?
Issue Number: None
Related PR: #65551, #66205
Problem Summary:
`threat-model.md` is what scanners, review agents and triagers use to
classify a report. It did not state the configuration its security
claims are made for:
- `enable_all_http_auth` (FE) is described as shipping on and as the
supported production posture, but the model never says production
must run with it on.
- `fe_meta_auth_token` (#65551) is not mentioned at all. It is the
credential of the FE-to-FE meta-service endpoints on port 8030
(`/image`, `/info`, `/version`, `/put`, `/journal_id`, `/role`,
`/check`), which sit outside the `/api/**` and `/rest/v2/**` surface
that §4.8 (11) covers, so a report about them had no section to land
in.
This change records maintainer decision M20: security claims are
stated for FEs running with `enable_all_http_auth` on and
`fe_meta_auth_token` set on every FE, and production must run that
way. Concretely:
- §4.5a: a `fe_meta_auth_token` row, "production must" wording on the
`enable_all_http_auth` row, and a short baseline paragraph. A finding
that needs either setting off or empty is
`OUT-OF-MODEL: non-default-build`; §4.13 is widened by one clause so
that this holds for the token although it ships empty.
- §4.8 (11): condition is the baseline; the meta-service endpoints are
added to its scope with the token as their credential; exclusion (c)
covers clusters outside the baseline.
- §4.10: (12) says production must keep the flag on; new (13) says how
to set the token (same value in every FE's `fe.conf`, restart, verify
with `ADMIN SHOW FRONTEND CONFIG`).
- §4.14: wave-6 decision record.
Code facts were checked against master: `MetaService.checkFromValidFe`,
the `AuthInterceptor` exclusions in `WebConfigurer`, the
`fe_meta_auth_token` definition in `Config`, and the sensitive-value
masking in `ConfigBase.getConfigInfo` used by
`ADMIN SHOW FRONTEND CONFIG`.
### Release note
None
### Check List (For Author)
- Test: No need to test (documentation-only change to `threat-model.md`;
no code changed)
- Behavior changed: No
- Does this need documentation: No
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]