Sentinel HTTP command server lacks access control – interceptor mechanism needed
Sentinel HTTP command server lacks access control – interceptor mechanism needed: a task in LegoFlow-SWE (Harbor dataset). Sentinel’s HTTP command server exposes endpoints (e.g., for modifying or retrieving flow rules) without any access verification. This poses a security risk when the Java…
The task
Sentinel’s HTTP command server exposes endpoints (e.g., for modifying or retrieving flow rules) without any access verification. This poses a security risk when the Java service is exposed to external networks. Attackers could construct requests to modify or read Sentinel’s runtime rules.
Part of Lego-X/LegoFlow-SWE.