igiguere opened a new pull request, #1632: URL: https://github.com/apache/solr/pull/1632
https://issues.apache.org/jira/browse/SOLR-14886 # Description Stack traces are considered a security risk. Please refer to OWASP for a full explanation: https://owasp.org/Top10/A05_2021-Security_Misconfiguration/ # Solution Add a property "hideStackTrace" to solr.xml. In NodeConfig, the default value is "false", for back-compatibility. Use the new property in ResponseUtils, to print out, or not, the stack trace. Adapt code that calls ResponseUtils. # Tests org.apache.solr.servlet.HideStackTraceTest : force an exception into the response, and assert that if hideStackTrace=true, the stack trace is not shown. # Checklist Please review the following and check all that apply: - [* ] I have reviewed the guidelines for [How to Contribute](https://wiki.apache.org/solr/HowToContribute) and my code conforms to the standards described there to the best of my ability. - [* ] I have created a Jira issue and added the issue ID to my pull request title. - [* ] I have given Solr maintainers [access](https://help.github.com/en/articles/allowing-changes-to-a-pull-request-branch-created-from-a-fork) to contribute to my PR branch. (optional but recommended) - [* ] I have developed this patch against the `main` branch. - [* ] I have run `./gradlew check`. - [* ] I have added tests for my changes. - [* ] I have added documentation for the [Reference Guide](https://github.com/apache/solr/tree/main/solr/solr-ref-guide) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org For additional commands, e-mail: issues-h...@solr.apache.org