[ https://issues.apache.org/jira/browse/HADOOP-10880?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14115431#comment-14115431 ]
Hudson commented on HADOOP-10880: --------------------------------- FAILURE: Integrated in Hadoop-Mapreduce-trunk #1880 (See [https://builds.apache.org/job/Hadoop-Mapreduce-trunk/1880/]) HADOOP-10880. Move HTTP delegation tokens out of URL querystring to a header. (tucu) (tucu: rev d1ae479aa5ae4d3e7ec80e35892e1699c378f813) * hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/security/token/delegation/web/DelegationTokenAuthenticationHandler.java * hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/security/token/delegation/web/DelegationTokenAuthenticatedURL.java * hadoop-common-project/hadoop-common/CHANGES.txt * hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/security/token/delegation/web/DelegationTokenAuthenticator.java * hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/security/token/delegation/web/TestWebDelegationToken.java * hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/security/token/delegation/web/TestDelegationTokenAuthenticationHandlerWithMocks.java > Move HTTP delegation tokens out of URL querystring to a header > -------------------------------------------------------------- > > Key: HADOOP-10880 > URL: https://issues.apache.org/jira/browse/HADOOP-10880 > Project: Hadoop Common > Issue Type: Bug > Components: security > Affects Versions: 2.4.1 > Reporter: Alejandro Abdelnur > Assignee: Alejandro Abdelnur > Priority: Blocker > Fix For: 2.6.0 > > Attachments: HADOOP-10880.patch, HADOOP-10880.patch, > HADOOP-10880.patch, HADOOP-10880.patch, HADOOP-10880.patch > > > Following up on a discussion in HADOOP-10799. > Because URLs are often logged, delegation tokens may end up in LOG files > while they are still valid. > We should move the tokens to a header. > We should still support tokens in the querystring for backwards compatibility. -- This message was sent by Atlassian JIRA (v6.2#6252)