Solr安全配置:开放query/select接口,保护其余管理页面
Got it, let's adjust your webdefault.xml to lock down Solr so only those two query endpoints are public, while everything else requires basic authentication. Here's a step-by-step breakdown tailored to your setup:
Step 1: Update webdefault.xml with Targeted Security Constraints
Security constraints in Jetty (the server bundled with Solr 5.3.0) are processed in order, so we'll first define the public access rules, then lock down everything else. Replace your existing configuration with this:
<!-- Allow public access to the two query endpoints --> <security-constraint> <web-resource-collection> <web-resource-name>Public Query Endpoints</web-resource-name> <url-pattern>/core/query</url-pattern> <url-pattern>/core/select</url-pattern> <!-- Note: Servlet URL patterns ignore query parameters, so this covers /core/query?* and /core/select?* automatically --> </web-resource-collection> <auth-constraint> <!-- Permit all users (including unauthenticated anonymous visitors) --> <role-name>*</role-name> </auth-constraint> </security-constraint> <!-- Require authentication for all other Solr resources --> <security-constraint> <web-resource-collection> <web-resource-name>Solr Authenticated Application</web-resource-name> <!-- Use /* to match every subpath under /solr --> <url-pattern>/*</url-pattern> </web-resource-collection> <auth-constraint> <role-name>core1-role</role-name> </auth-constraint> </security-constraint> <login-config> <auth-method>BASIC</auth-method> <realm-name>Test Realm</realm-name> </login-config>
Key Notes on This Configuration:
- Order Matters: The public access rule comes first, so any request matching
/core/queryor/core/selectwill bypass authentication. All other requests fall into the second constraint and require login. - URL Pattern Matching: You don't need to include
?in the patterns—Servlet containers ignore query parameters when matching URL patterns, so/core/querycovers all variations like/core/query?q=test. - Replace
coreif Needed: If your actual core name isn'tcore, swap it out in the URL patterns (e.g.,/my-custom-core/query).
Step 2: Configure a User with the Required Role
Jetty uses a realm.properties file to manage users and roles. Navigate to your Solr example/etc folder, open realm.properties, and add a user assigned to core1-role:
# Format: username: password, role1, role2... solr-admin: MySecurePassword123!, core1-role
- Pick a strong password (avoid plain text in production if possible, but Solr 5.3.0's default realm uses plain text for simplicity).
Step 3: Restart Solr and Test
Stop your Solr service, then restart it to apply the new configuration. Test the following:
- Public Endpoints: Visit
http://localhost:8983/solr/core/query?q=*orhttp://localhost:8983/solr/core/select?q=*—you should get results immediately without a login prompt. - Protected Paths: Try accessing
http://localhost:8983/solr/orhttp://localhost:8983/solr/core/admin—a basic authentication window should pop up. Enter the username and password you set inrealm.propertiesto gain access.
内容的提问来源于stack exchange,提问作者Dr Jay

