You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Solr安全配置:开放query/select接口,保护其余管理页面

Solr 5.3.0 Security Configuration: Restrict Access to Only Query Endpoints

Got it, let's adjust your webdefault.xml to lock down Solr so only those two query endpoints are public, while everything else requires basic authentication. Here's a step-by-step breakdown tailored to your setup:

Step 1: Update webdefault.xml with Targeted Security Constraints

Security constraints in Jetty (the server bundled with Solr 5.3.0) are processed in order, so we'll first define the public access rules, then lock down everything else. Replace your existing configuration with this:

<!-- Allow public access to the two query endpoints -->
<security-constraint>
  <web-resource-collection>
    <web-resource-name>Public Query Endpoints</web-resource-name>
    <url-pattern>/core/query</url-pattern>
    <url-pattern>/core/select</url-pattern>
    <!-- Note: Servlet URL patterns ignore query parameters, so this covers /core/query?* and /core/select?* automatically -->
  </web-resource-collection>
  <auth-constraint>
    <!-- Permit all users (including unauthenticated anonymous visitors) -->
    <role-name>*</role-name>
  </auth-constraint>
</security-constraint>

<!-- Require authentication for all other Solr resources -->
<security-constraint>
  <web-resource-collection>
    <web-resource-name>Solr Authenticated Application</web-resource-name>
    <!-- Use /* to match every subpath under /solr -->
    <url-pattern>/*</url-pattern>
  </web-resource-collection>
  <auth-constraint>
    <role-name>core1-role</role-name>
  </auth-constraint>
</security-constraint>

<login-config>
  <auth-method>BASIC</auth-method>
  <realm-name>Test Realm</realm-name>
</login-config>

Key Notes on This Configuration:

  • Order Matters: The public access rule comes first, so any request matching /core/query or /core/select will bypass authentication. All other requests fall into the second constraint and require login.
  • URL Pattern Matching: You don't need to include ? in the patterns—Servlet containers ignore query parameters when matching URL patterns, so /core/query covers all variations like /core/query?q=test.
  • Replace core if Needed: If your actual core name isn't core, swap it out in the URL patterns (e.g., /my-custom-core/query).

Step 2: Configure a User with the Required Role

Jetty uses a realm.properties file to manage users and roles. Navigate to your Solr example/etc folder, open realm.properties, and add a user assigned to core1-role:

# Format: username: password, role1, role2...
solr-admin: MySecurePassword123!, core1-role
  • Pick a strong password (avoid plain text in production if possible, but Solr 5.3.0's default realm uses plain text for simplicity).

Step 3: Restart Solr and Test

Stop your Solr service, then restart it to apply the new configuration. Test the following:

  • Public Endpoints: Visit http://localhost:8983/solr/core/query?q=* or http://localhost:8983/solr/core/select?q=*—you should get results immediately without a login prompt.
  • Protected Paths: Try accessing http://localhost:8983/solr/ or http://localhost:8983/solr/core/admin—a basic authentication window should pop up. Enter the username and password you set in realm.properties to gain access.

内容的提问来源于stack exchange,提问作者Dr Jay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:08:40