[ 
https://issues.apache.org/jira/browse/SOLR-6925?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14268901#comment-14268901
 ] 

ASF subversion and git services commented on SOLR-6925:
-------------------------------------------------------

Commit 1650213 from [~erickoerickson] in branch 'dev/branches/branch_5x'
[ https://svn.apache.org/r1650213 ]

SOLR-6925: Back out changes having to do with SOLR-5287 (editing configs from 
admin UI)

> Back out changes having to do with SOLR-5287 (editing configs from admin UI)
> ----------------------------------------------------------------------------
>
>                 Key: SOLR-6925
>                 URL: https://issues.apache.org/jira/browse/SOLR-6925
>             Project: Solr
>          Issue Type: Bug
>    Affects Versions: 5.0, Trunk
>            Reporter: Erick Erickson
>            Assignee: Erick Erickson
>            Priority: Blocker
>         Attachments: SOLR-6925.patch
>
>
> Should have something today/tomorrow. The history here is that I had this 
> bright idea to edit files directly from the admin UI, especially schema.xml 
> and solrxconifg.xml. Brilliant I sez to myself... except it's a significant 
> security hole and I'm really glad that was pointed out before we released it 
> in 4x.
> So we pulled it completely from 4.x and made it something in 5.x (then trunk) 
> that you could enable (disabled by default) if you wanted to live dangerously 
> and "we'd deal with it later". Well it's later.
> Given all the work for managed schemas and the like in the interim, I think 
> this is cruft that should be removed completely from current trunk and 5x.
> Marking it as a blocker so we don't release 5x with this in it or we'll have 
> back-compat issues. Should have a fix in very quickly.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@lucene.apache.org
For additional commands, e-mail: dev-h...@lucene.apache.org

Reply via email to