Uploaded image for project: 'Dev - Nexus Repo'
  1. Dev - Nexus Repo
  2. NEXUS-27538

Prevent accidental tagging of all components

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: New
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 3.30.1
    • Fix Version/s: None
    • Component/s: Tags
    • Labels:
    • Notability:
      4

      Description

      The following call, will result in all components In Nexus being tagged. The reason is that by accident, the URL with was not escaped within quotes "".

      curl -v -u admin:admin123 -X POST http://localhost:8081/service/rest/v1/tags/associate/testtagging-1?wait=true&repository=maven-releases-s3&group=com.sonatype.test&name=simple
      

      This is a very simple mistake to make and could cause Nexus to become unresponsive.

      To prevent these type of accidents, if no search criteria is provided then Nexus should not tag. There could be a specific parameter call for tagging all components if someone really wanted to intentionally tag all components in Nexus (seems unlikely).

        Attachments

          Activity

            People

            Assignee:
            Unassigned Unassigned
            Reporter:
            msurani Mahendra Surani
            CC:
            Dinesh Shivakoti
            Last Updated By:
            Michael Oliverio Michael Oliverio
            Votes:
            2 Vote for this issue
            Watchers:
            4 Start watching this issue

              Dates

              Created:
              Updated:
              Date of First Response:

                tigCommentSecurity.panel-title