Apache Solr 9.8.1核心授权规则不生效问题求助
Solr 9.8.1核心特定授权规则不生效问题
我刚安装Solr 9.8.1并创建了核心,配置了若干授权规则,但无法限制对指定核心的访问。通用访问规则正常生效,但核心特定规则完全不匹配任何请求。
当前配置
"class":"solr.RuleBasedAuthorizationPlugin", "permissions":[ {"name": "read-test-core-1", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["*"], "index": 1}, {"name": "read-test-core-2", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["/"], "index": 2}, {"name": "read-test-core-3", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["/*"], "index": 3}, {"name": "read-test-core-4", "role": ["reader-of-test-core"], "collection": ["test-core"], "path": ["/select"], "index": 4}, {"name": "all", "role": ["admin"], "index": 5} ], "user-role":{ "admin-user": ["admin"], "core-user": ["reader-of-test-core"] }
日志信息
This resource is configured to have a permission { "name":"all", "role":["admin"], "index":5}, The principal BasicAuthPlugin [username=core-user,pwd=*****] does not have the right role
我尝试了上述所有路径配置均无效,只有admin规则能匹配请求。若给"core-user"配置全局读取权限(内置read权限),该用户可执行select查询,但无法限制其仅访问"test-core"核心,不清楚哪里操作有误。
问题原因与解决方案
核心问题是配置字段误用:Solr单实例(Standalone)模式下,指定核心的字段是core,而非collection。collection字段仅适用于SolrCloud集群模式。
修改权限配置,将所有collection字段替换为core,精简后的有效配置示例:
"permissions":[ {"name": "read-test-core", "role": ["reader-of-test-core"], "core": ["test-core"], "path": ["/*"], "index": 1}, {"name": "all", "role": ["admin"], "index": 5} ]
额外注意事项:
- 权限
index值越小优先级越高,核心特定规则需放在通用规则前 - 路径
["/*"]可覆盖该核心下所有请求接口(包括/select) - 修改配置后需重启Solr或通过Admin页面重新加载授权插件
内容的提问来源于stack exchange,提问作者user2323470
相关产品推荐
相关产品推荐

