Skip to content

Add https to BrokerView restricted list#2073

Merged
cshannon merged 1 commit into
apache:mainfrom
cshannon:add-https-deny
Jun 5, 2026
Merged

Add https to BrokerView restricted list#2073
cshannon merged 1 commit into
apache:mainfrom
cshannon:add-https-deny

Conversation

@cshannon
Copy link
Copy Markdown
Contributor

@cshannon cshannon commented Jun 4, 2026

This adds https to the denied list eventhough there is currently no https discovery protocol. This is being done just for extra defense in depth in case a protocol is added in the future. There's also already other checks in place (we deny remote protocols by default already, etc) so this is just precautionary.

This adds https to the denied list eventhough there is currently no
https discovery protocol. This is being done just for extra defense in
depth in case a protocol is added in the future. There's also already
other checks in place (we deny remote protocols by default already, etc)
so this is just precautionary.
@cshannon cshannon merged commit dfa00d0 into apache:main Jun 5, 2026
19 of 20 checks passed
@github-project-automation github-project-automation Bot moved this from Backlog to Done in Apache ActiveMQ v6.3.0 Jun 5, 2026
@cshannon cshannon deleted the add-https-deny branch June 5, 2026 17:19
cshannon added a commit that referenced this pull request Jun 5, 2026
This adds https to the denied list eventhough there is currently no
https discovery protocol. This is being done just for extra defense in
depth in case a protocol is added in the future. There's also already
other checks in place (we deny remote protocols by default already, etc)
so this is just precautionary.

(cherry picked from commit dfa00d0)
cshannon added a commit that referenced this pull request Jun 5, 2026
This adds https to the denied list eventhough there is currently no
https discovery protocol. This is being done just for extra defense in
depth in case a protocol is added in the future. There's also already
other checks in place (we deny remote protocols by default already, etc)
so this is just precautionary.

(cherry picked from commit dfa00d0)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants