Bug 2149536 - [Ceph-Dashboard] Allow CORS if the origin ip is known
Summary: [Ceph-Dashboard] Allow CORS if the origin ip is known
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Ceph Storage
Classification: Red Hat Storage
Component: Ceph-Dashboard
Version: 6.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: 6.0
Assignee: Nizamudeen
QA Contact: Sayalee
Eliska
URL:
Whiteboard:
Depends On:
Blocks: 2126050
TreeView+ depends on / blocked
 
Reported: 2022-11-30 04:24 UTC by Nizamudeen
Modified: 2023-03-20 19:00 UTC (History)
8 users (show)

Fixed In Version: ceph-17.2.5-38.el9cp
Doc Type: Enhancement
Doc Text:
.Cross origin resource sharing is now allowed Previously, IBM developers were facing issues with their storage insights product when they tried to ping the REST API using their front-end because of the tight cross origin resource sharing (CORS) policies setup in the REST API. With this release, the `cross_origin_url` option is added, which can be set to a particular URL. The REST API now allows communicating with only that URL. .Example ---- [ceph: root@host01 /]# ceph config set mgr mgr/dashboard/cross_origin_url http://localhost:4200 ----
Clone Of:
: 2149653 (view as bug list)
Environment:
Last Closed: 2023-03-20 18:59:40 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github ceph ceph pull 49060 0 None Merged mgr/dashboard: allow cross origin when the url is set 2022-11-30 04:27:49 UTC
Red Hat Issue Tracker RHCEPH-5713 0 None None None 2022-11-30 04:30:30 UTC
Red Hat Issue Tracker RHCSDASH-867 0 None None None 2022-11-30 04:30:32 UTC
Red Hat Product Errata RHBA-2023:1360 0 None None None 2023-03-20 19:00:50 UTC

Comment 1 Ken Dreyer (Red Hat) 2022-12-16 03:15:09 UTC
We're at the RC deadline, so we'll have to fix this in a subsequent release after 6.0.

Comment 16 Veera Raghava Reddy 2023-01-12 08:54:39 UTC
Hi Nizam, Avan,
Need to include PR https://github.com/ceph/ceph/pull/49329 [mgr/dashboard: allow Origin URL for CORS if present in config]
On 5.3 also needs to be ported. IBM team tried to test Storage Insights on 5.3 GA and got errors to access Dashboard using Rest API.
Marking this as Blocker

Comment 18 Veera Raghava Reddy 2023-01-12 09:24:17 UTC
Hi Nizam,
Thanks for the update and for taking care of backport to 6.0

Comment 21 errata-xmlrpc 2023-03-20 18:59:40 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Red Hat Ceph Storage 6.0 Bug Fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:1360


Note You need to log in before you can comment on or make changes to this bug.