You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache Solr 9.8.1核心授权规则不生效问题求助

Solr 9.8.1核心特定授权规则不生效问题

我刚安装Solr 9.8.1并创建了核心,配置了若干授权规则,但无法限制对指定核心的访问。通用访问规则正常生效,但核心特定规则完全不匹配任何请求。

当前配置

"class":"solr.RuleBasedAuthorizationPlugin",
"permissions":[
    {"name": "read-test-core-1", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["*"],       "index": 1},
    {"name": "read-test-core-2", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["/"],       "index": 2},
    {"name": "read-test-core-3", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["/*"],      "index": 3},
    {"name": "read-test-core-4", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["/select"], "index": 4},
    {"name": "all",              "role": ["admin"],                                                                 "index": 5}
],
"user-role":{
    "admin-user": ["admin"],
    "core-user":  ["reader-of-test-core"]
}

日志信息

This resource is configured to have a permission {
  "name":"all",
  "role":["admin"],
  "index":5}, The principal BasicAuthPlugin [username=core-user,pwd=*****] does not have the right role

我尝试了上述所有路径配置均无效,只有admin规则能匹配请求。若给"core-user"配置全局读取权限(内置read权限),该用户可执行select查询,但无法限制其仅访问"test-core"核心,不清楚哪里操作有误。


问题原因与解决方案

核心问题是配置字段误用:Solr单实例(Standalone)模式下,指定核心的字段是core,而非collection。collection字段仅适用于SolrCloud集群模式。

修改权限配置,将所有collection字段替换为core,精简后的有效配置示例:

"permissions":[
    {"name": "read-test-core", "role": ["reader-of-test-core"], "core": ["test-core"], "path": ["/*"], "index": 1},
    {"name": "all",              "role": ["admin"], "index": 5}
]

额外注意事项:

  • 权限index值越小优先级越高,核心特定规则需放在通用规则前
  • 路径["/*"]可覆盖该核心下所有请求接口(包括/select)
  • 修改配置后需重启Solr或通过Admin页面重新加载授权插件

内容的提问来源于stack exchange,提问作者user2323470

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 02:41:06