Skip to content

Commit

Permalink
Remove changes in security.policy
Browse files Browse the repository at this point in the history
Signed-off-by: Craig Perkins <[email protected]>
  • Loading branch information
cwperks committed Dec 15, 2022
1 parent f18332b commit 134bcb0
Showing 1 changed file with 1 addition and 18 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -41,11 +41,6 @@ grant codeBase "${codebase.opensearch-secure-sm}" {
permission java.security.AllPermission;
};

grant codeBase "${codebase.opensearch-authn}" {
// this is required by jackson databind to access declared methods for javax.security.Principal class via StringPrincipal.java
permission java.security.AllPermission;
};

//// Opensearch core:
//// These are only allowed inside the server jar, not in plugins
grant codeBase "${codebase.opensearch}" {
Expand Down Expand Up @@ -79,16 +74,6 @@ grant codeBase "${codebase.opensearch-plugin-classloader}" {
permission java.lang.RuntimePermission "createClassLoader";
};

grant codeBase "${codebase.jackson-databind}" {
// needed by jackson-databind ObjectMapper.readValue
permission java.lang.reflect.ReflectPermission "suppressAccessChecks";
permission java.lang.RuntimePermission "accessDeclaredMembers";
};

grant codeBase "${codebase.cxf-rt-rs-security-jose}" {
permission java.lang.RuntimePermission "setContextClassLoader";
};

grant codeBase "${codebase.jna}" {
// for registering native methods
permission java.lang.RuntimePermission "accessDeclaredMembers";
Expand Down Expand Up @@ -117,7 +102,7 @@ grant {

permission java.lang.RuntimePermission "accessDeclaredMembers";
permission java.lang.reflect.ReflectPermission "suppressAccessChecks";

// Allow read access to all system properties
permission java.util.PropertyPermission "*", "read";

Expand Down Expand Up @@ -200,6 +185,4 @@ grant {
permission java.io.FilePermission "/sys/fs/cgroup/memory", "read";
permission java.io.FilePermission "/sys/fs/cgroup/memory/-", "read";

// needed by cxf-rt-rs-security-jose
permission java.lang.RuntimePermission "setContextClassLoader";
};

0 comments on commit 134bcb0

Please sign in to comment.