CARVIEW |
Select Language
HTTP/2 200
date: Sat, 26 Jul 2025 01:41:29 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"d90e58dbac2756397a36c44ca46afa8d"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=AzzHoH7pGgCbWLPwxUkBL4T%2Fz21FqP2Rv%2FnVWnf1GVY02Zo%2BExYwgtSJRltqSkyT%2BWL49iRmE0SvzsimTKQGn06kpZDKdVCr1yjatbkAs80pUmFl8DfA6BI%2FePWswmX3EMjyJmXapEKCG0ZpD%2BsgxKgkejtGFDMB61B%2BdlUEnitKu9rsuiX%2F2f9oS7rNjdS5fmDGhZE1lu0v6aYPkKVdj34lH89cyVyRVJILLjY3kwzxOD%2BcxS7HzwtwnPR62Ki6Vv3w%2F%2B9R9fHfv1QauJNU5A%3D%3D--9%2BcFTLh9LsHbSnp4--gDaAfiH8VdAM9KVW2Fe%2BrA%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.341295566.1753494089; Path=/; Domain=github.com; Expires=Sun, 26 Jul 2026 01:41:29 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Sun, 26 Jul 2026 01:41:29 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: CD36:1C79A4:984B9:F2008:68843249
Tags · Asquera/elasticsearch-http-basic · GitHub
Toggle v1.5.0's commit message
Toggle v1.4.0.Beta1's commit message
Toggle v1.3.0-security-fix's commit message
Toggle v1.2.0-security-fix's commit message
Skip to content
Navigation Menu
{{ message }}
This repository was archived by the owner on Mar 4, 2019. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 120
Tags: Asquera/elasticsearch-http-basic
Tags
v1.5.0
ES compatiblity. Added - allow disabling ipwhitelist by setting its value to `false` - updated pom to depend on elasticsearch-parent project - travis test matrix for different ES versions Changed - restored default healthcheck for authenticated users - unauthenticated healthcheck for `/` returns `"{\"OK\":{}}"` - thanks @feaster83
v1.4.0.Beta1
ES 1.4.0.Beta1 compatibility
v1.3.0-security-fix
fixed security problem in ip authentication. ES 1.3.0 compatible security problem introduced in commit 53d1cf8 changes: - remove usage of 'Host' header to identify client's ip - the request ip is used to ip authenticate direct connected clients - add usage of trusted proxy chain - the trusted proxy chain is used to ip authenticate indirect connected clients - added unit and integration tests - updated log messages
v1.2.0-security-fix
Security Fix for Ip Authentication compatible with ES 1.2.0 Due to implementation of how the ip of the client is obtained it is very easy for an attacker to authenticate its ip by setting the ip in the 'Host' header or as first ip in the 'X-Forwarded-For' header
PreviousNext
You can’t perform that action at this time.