[ https://issues.apache.org/jira/browse/HADOOP-10379?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13921249#comment-13921249 ]
Haohui Mai edited comment on HADOOP-10379 at 3/5/14 7:18 PM: ------------------------------------------------------------- For the branch-1 patch, I've run the test-patch script and the patch passed all the unit tests. was (Author: wheat9): I've run the test-patch script and it passes all the unit tests. > Protect authentication cookies with the HttpOnly and Secure flags > ----------------------------------------------------------------- > > Key: HADOOP-10379 > URL: https://issues.apache.org/jira/browse/HADOOP-10379 > Project: Hadoop Common > Issue Type: Improvement > Reporter: Haohui Mai > Assignee: Haohui Mai > Fix For: 2.4.0 > > Attachments: HADOOP-10379-branch-1.000.patch, HADOOP-10379.000.patch, > HADOOP-10379.001.patch, HADOOP-10379.002.patch > > > Browser vendors have adopted proposals to enhance the security of HTTP > cookies. For example, the server can mark a cookie as {{Secure}} so that it > will not be transfer via plain-text HTTP protocol, and the server can mark a > cookie as {{HttpOnly}} to prohibit the JavaScript to access that cookie. > This jira proposes to adopt these flags in Hadoop to protect the HTTP cookie > used for authentication purposes. -- This message was sent by Atlassian JIRA (v6.2#6252)