[ https://issues.apache.org/jira/browse/OAK-4959?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15848015#comment-15848015 ]
Chetan Mehrotra commented on OAK-4959: -------------------------------------- Removing this from 1.6.1 for now as changes are bigger. For now the application should restrict write access to paths under /jcr:system to admin user and that would meet the requirements. Going forward the validator based approach would be implemented > Review the security aspect of bundling configuration > ---------------------------------------------------- > > Key: OAK-4959 > URL: https://issues.apache.org/jira/browse/OAK-4959 > Project: Jackrabbit Oak > Issue Type: Task > Components: documentmk > Reporter: Chetan Mehrotra > Assignee: Chetan Mehrotra > Labels: bundling > Fix For: 1.8 > > Attachments: OAK-4959-v1.patch > > > The config for node bundling feature in DocumentNodeStore is currently stored > under {{jcr:system/rep:documentStore/bundlor}}. This task is meant to > * Review the access control aspect - This config should be only updatetable > by system admin > * Config under here should be writeable via JCR api -- This message was sent by Atlassian JIRA (v6.3.15#6346)