Uploaded image for project: 'JBeret'
  1. JBeret
  2. JBERET-591

$local user should not be saved to job repository

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Major
    • None
    • None
    • jberet-core
    • None

    Description

      The special user $local in WildFly JBOSS-LOCAL-USER realm is used behind the scene to authenticate a remote client invocation over remote or remote+http connection within the same host, when the client does not explicitly configure any sasl mechanism. So it should not be exported outside WildFly authentication and authorization for other purpose.

      JBeret saves the current user in job repository solely for the purpose of restarting the current job execution that may fail or be stopped. In addition, once saved in job repository, the restart may be performed by other node in the cluster, where the saved user no longer holds true.

      Attachments

        Issue Links

          Activity

            People

              weli@redhat.com Weinan Li
              cfang@redhat.com Cheng Fang
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated: