yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #04800
[Bug 1195700] Re: NovaWebSocketProxy - Enable no_parent and file_only security
** Changed in: nova
Status: Fix Committed => Fix Released
** Changed in: nova
Milestone: None => havana-3
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to OpenStack Compute (nova).
https://bugs.launchpad.net/bugs/1195700
Title:
NovaWebSocketProxy - Enable no_parent and file_only security
Status in OpenStack Compute (Nova):
Fix Released
Bug description:
The websockify package was recently upgraded to version 0.5.1, which added two
parameters that provide additional security:
* no_parent
* file_only
https://github.com/kanaka/websockify/commit/888e75a8fb99ab2c06247e34d3a928acda42affe
This version is available in PyPi -
http://pypi.python.org/packages/source/w/websockify/websockify-0.5.1.tar.gz
Nova should upgrade it's required version for websockify, and setting
these parameters while creating and starting the NovaWebSockets proxy
would ensure better security
To manage notifications about this bug go to:
https://bugs.launchpad.net/nova/+bug/1195700/+subscriptions