Bläddra i källkod

默认关闭 actuator,消除actuator 未授权访问漏洞

MaxKey 1 månad sedan
förälder
incheckning
cf9e66ca3f

+ 3 - 3
maxkey-webs/maxkey-web-maxkey/src/main/resources/application-maxkey.properties

@@ -268,11 +268,11 @@ maxkey.saml.v20.sp.issuing.entity.id                            =client.maxkey.o
 ############################################################################
 #Management endpoints configuration                                        #
 ############################################################################
-management.security.enabled                     =false
+management.endpoints.enabled-by-default=false
 #management.endpoints.jmx.exposure.include=health,info
 #management.endpoints.web.exposure.include=metrics,health,info,env,prometheus
-management.endpoints.web.exposure.include       =*
-management.endpoint.health.show-details         =ALWAYS
+#management.endpoints.web.exposure.include       =*
+#management.endpoint.health.show-details         =ALWAYS
 management.health.redis.enabled                 =false
 management.health.mail.enabled                  =false
 

+ 3 - 3
maxkey-webs/maxkey-web-mgt/src/main/resources/application-maxkey-mgt.properties

@@ -197,11 +197,11 @@ maxkey.job.cron.enable                          =true
 ############################################################################
 #Management endpoints configuration                                        #
 ############################################################################
-management.security.enabled                     =false
+management.endpoints.enabled-by-default=false
 #management.endpoints.jmx.exposure.include=health,info
 #management.endpoints.web.exposure.include=metrics,health,info,env,prometheus
-management.endpoints.web.exposure.include       =*
-management.endpoint.health.show-details         =ALWAYS
+#management.endpoints.web.exposure.include       =*
+#management.endpoint.health.show-details         =ALWAYS
 management.health.redis.enabled                 =false
 management.health.mail.enabled                  =false
 

+ 3 - 3
maxkey-webs/maxkey-web-openapi/src/main/resources/application-maxkey-openapi.properties

@@ -195,11 +195,11 @@ maxkey.job.cron.enable                          =true
 ############################################################################
 #Management endpoints configuration                                        #
 ############################################################################
-management.security.enabled                     =false
+management.endpoints.enabled-by-default=false
 #management.endpoints.jmx.exposure.include=health,info
 #management.endpoints.web.exposure.include=metrics,health,info,env,prometheus
-management.endpoints.web.exposure.include       =*
-management.endpoint.health.show-details         =ALWAYS
+#management.endpoints.web.exposure.include       =*
+#management.endpoint.health.show-details         =ALWAYS
 management.health.redis.enabled                 =false
 management.health.mail.enabled                  =false