[SOLR-12770] [CVE-2017-3164] Make it possible to configure a shards whitelist for master/slave - Solr - [issue]
...The "shards" parameter does not have a corresponding white list mechanism, so it can request any URL, and the content of the HTTP response will be returned.For legacy master/slave clusters, ...    Author: Jan Høydahl , 2019-06-08, 14:57
[SOLR-12695] Improve XML Query Parser documentation - Solr - [issue]
...The xmlparser (XML Query Parser) documentation at is very shallow. This complex query parser needs in-depth docum...    Author: Jan Høydahl , 2019-06-08, 14:57
[SOLR-12791] Add Metrics reporting for AuthenticationPlugin - Solr - [issue]
...Propose to add Metrics support for all Auth plugins. Will let abstract AuthenticationPlugin base class implement SolrMetricProducer and keep the counters, such as: requests req authenticated...    Author: Jan Høydahl , 2019-06-08, 14:57
[SOLR-11886] Remove last remnant of old Admin UI - Solr - [issue]
...In SOLR-10042 we removed the old jQuery based Admin UI and got rid of the non-working copy-to-clipboard feature. This issue is to remove the unused file zeroclipboard.swf from the UI.Thanks ...    Author: Jan Høydahl , 2019-06-08, 15:14
[SOLR-12292] Make it easier to configure Solr with CORS - Solr - [issue]
...While working on SOLR-8207 I wanted to collect info from other SolrCloud nodes from the AdminUI. However this is blocked by CORS policy. In that Jira I instead did the fan-out on the Solr se...    Author: Jan Høydahl , 2019-06-08, 15:14
[SOLR-12121] JWT Authentication plugin - Solr - [issue]
...A new Authentication plugin that will accept a Json Web Token (JWT) in the Authorization header and validate it by checking the cryptographic signature. The plugin will not perform the authe...    Author: Jan Høydahl , 2019-06-08, 15:14
[SOLR-12459] Add number of documents to the Collection Overview tab - Solr - [issue]
...Today we have:Config nameMax shards per nodeReplication factorAuto-add replicasRouter nameLet's add the total number of documents in the collection to the overview page as well. And perhaps ...    Author: Jan Høydahl , 2019-06-08, 15:14
[SOLR-12350] Do not use docValues as stored for _str (copy)fields in _default configset - Solr - [issue]
...When improving data-driven mode in SOLR-9526 we discussed back and forth whether to set useDocValuesAsStored for the *_str copy of text fields. This dynamic field is currently defined as<...    Author: Jan Høydahl , 2019-06-08, 15:14
[SOLR-12195] Remove deprecated SolrRequest#setBasicAuthCredentials methods - Solr - [issue]
...Followup for SOLR-12194. This will remove the deprecated SolrJ code from v8.0.This should also provide better refguide docs on the topic....    Author: Jan Høydahl , 2019-06-08, 15:12
[SOLR-12131] Authorization plugin support for getting user's roles from the outside - Solr - [issue]
...Currently the RuleBasedAuthorizationPlugin relies on explicitly mapping users to roles. However, when users are authenticated by an external Identity service (e.g. JWT as implemented in SOLR...    Author: Jan Høydahl , 2019-06-08, 15:12