bamaer opened a new pull request, #8402:
URL: https://github.com/apache/hop/pull/8402

   …arning. fixes #8391
   
   - hop-web.adoc: correct the mode NONE description (/ui open by design, 
/hop/* default-denied) and document allowUnauthenticatedServerApi / 
HOP_WEB_ALLOW_UNAUTHENTICATED_SERVER_API as the execution-server opt-in. Add an 
IMPORTANT note that EXTERNAL delegates rather than enforces.
   - THREAT_MODEL.md: add Hop Web as a distinct deployment, scope the 
enable_auth assumption to hop-server, and describe the per-mode boundary.
   - HopWebEntryPoint: log a warning when a session has no principal in a mode 
other than NONE, so EXTERNAL without a container security-constraint no longer 
fails open silently.
   
   **Please** add a meaningful description for your change here
   
   ------------------------
   
   Thank you for your contribution! Follow this checklist to help us 
incorporate your contribution quickly and easily:
   - [x] Run `mvn clean install apache-rat:check` to make sure basic checks 
pass. A more thorough check will be performed on your pull request 
automatically.
   - [x] If you have a group of commits related to the same change, please 
squash your commits into one and force push your branch using `git rebase -i`.
   - [x] Mention the appropriate issue in your description (for example: 
`addresses #123`), if applicable.
   
   To make clear that you license your contribution under the [Apache License 
Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   you have to acknowledge this by using the following check-box.
   
   - [x] I hereby declare this contribution to be licensed under the [Apache 
License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   - [ ] In any other case, please file an [Apache Individual Contributor 
License Agreement](https://www.apache.org/licenses/icla.pdf).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to