[ https://issues.apache.org/jira/browse/MESOS-7414?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Adam B updated MESOS-7414: -------------------------- Labels: mesosphere operator security (was: mesosphere operator) > Enable authorization for master's logging API calls: GET_LOGGING_LEVEL and > SET_LOGGING_LEVEL > --------------------------------------------------------------------------------------------- > > Key: MESOS-7414 > URL: https://issues.apache.org/jira/browse/MESOS-7414 > Project: Mesos > Issue Type: Task > Components: HTTP API, master > Reporter: Alexander Rojas > Labels: mesosphere, operator, security > > The Operator API calls {{GET_LOGGING_LEVEL}} and {{SET_LOGGING_LEVEL}}, as > well as the v0 endpoint {{/logging/toggle}} lack authorization so any > recognized user will be able to change the logging level of a given master. > Note that there are already actions defined for authorization of these > actions as they were already implemented in the agent. -- This message was sent by Atlassian JIRA (v6.3.15#6346)