Only allow localhost to access the status page, by default
authorlajoie <lajoie@ab3bd59b-922f-494d-bb5f-6f0a3c29deca>
Wed, 5 Aug 2009 16:43:51 +0000 (16:43 +0000)
committerlajoie <lajoie@ab3bd59b-922f-494d-bb5f-6f0a3c29deca>
Wed, 5 Aug 2009 16:43:51 +0000 (16:43 +0000)
git-svn-id: https://subversion.switch.ch/svn/shibboleth/java-idp/branches/REL_2@2878 ab3bd59b-922f-494d-bb5f-6f0a3c29deca

src/main/webapp/WEB-INF/web.xml

index a4d5cae..ee8df5a 100644 (file)
     <servlet>
         <servlet-name>Status</servlet-name>
         <servlet-class>edu.internet2.middleware.shibboleth.idp.StatusServlet</servlet-class>
+        
+        <!-- Space separated list of CIDR blocks allowed to access the status page -->
+        <init-param>
+            <param-name>AllowedIPs</param-name>
+            <param-value>127.0.0.1/32 ::1/128</param-value>
+        </init-param>
+        
         <load-on-startup>2</load-on-startup>
     </servlet>