[ https://issues.apache.org/jira/browse/SOLR-8440?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16001435#comment-16001435 ]
Jan Høydahl commented on SOLR-8440: ----------------------------------- I also vote for keeping it user friendly first and foremost. However, one advantage of {{solr.httpclient.config}} is that the plaintext password will not be available as a system property. If it is passed in to Solr as system property it will be visible both in Admin UI and in {{ps -efwww}}. So if {{bin/solr auth....}} is able to create the password file inside {{$SOLR_VAR_DIR}} for the instance, i.e. next to {{solr.in.sh}} and update solr.in.sh accordingly. > Script support for enabling basic auth > -------------------------------------- > > Key: SOLR-8440 > URL: https://issues.apache.org/jira/browse/SOLR-8440 > Project: Solr > Issue Type: New Feature > Components: scripts and tools > Reporter: Jan Høydahl > Assignee: Ishan Chattopadhyaya > Labels: authentication, security > Attachments: SOLR-8440.patch, SOLR-8440.patch, SOLR-8440.patch, > SOLR-8440.patch, SOLR-8440.patch, SOLR-8440.patch > > > Now that BasicAuthPlugin will be able to work without an AuthorizationPlugin > (SOLR-8429), it would be sweet to provide a super simple way to "Password > protect Solr"™ right from the command line: > {noformat} > bin/solr basicAuth -adduser -user solr -pass SolrRocks > {noformat} > It would take the mystery out of enabling one single password across the > board. The command would do something like this > # Check if HTTPS is enabled, and if not, print a friendly warning > # Check if {{/security.json}} already exists > ## NO => create one with only plugin class defined > ## YES => Abort if exists but plugin is not {{BasicAuthPlugin}} > # Using security REST API, add the new user -- This message was sent by Atlassian JIRA (v6.3.15#6346) --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@lucene.apache.org For additional commands, e-mail: dev-h...@lucene.apache.org