Skip to content

Cross origin policy blocks access to webconsole #23

Closed
@RobertFloor

Description

@RobertFloor
SUMMARY

The Cross Origin (CORS) policy in etc/jolokia-acces.xml block access to the web console. I believe it is the problem as mentioned on stack overflow: https://stackoverflow.com/a/71207182 . This part blocks access to webconsole from my remote machine:

<allow-origin>*://0.0.0.0*</allow-origin>

It works if I change it to

<allow-origin>*://*</allow-origin>

ISSUE TYPE
  • Bug Report
STEPS TO REPRODUCE

Default installation

EXPECTED RESULTS

Get access to the web console

ACTUAL RESULTS

Obtained a blank screen after login in with the correct credentials

root@amq1 etc]# cat jolokia-access.xml
<?xml version="1.0" encoding="utf-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements.  See the NOTICE file
distributed with this work for additional information
regarding copyright ownership.  The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License.  You may obtain a copy of the License at

  http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied.  See the License for the
specific language governing permissions and limitations
under the License.
-->

<!-- This policy file controls the Jolokia JMX-HTTP bridge security options for the web console.
   see: https://jolokia.org/reference/html/security.html -->
<restrict>

    <cors>
        <!-- Allow cross origin access from 0.0.0.0 ... -->
        <allow-origin>*://0.0.0.0*</allow-origin>


        <!-- Options from this point on are auto-generated by Create.java from the Artemis CLI -->
        <!-- Check for the proper origin on the server side, too -->
        <strict-checking/>
    </cors>

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugfixesFixes that resolve issues. SHOULD not be used for minor enhancements

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions