killbill-memoizeit

server: disabled RBAC in the default shiro.ini Signed-off-by:

8/9/2013 9:01:21 PM

Details

diff --git a/server/src/main/webapp/WEB-INF/shiro.ini b/server/src/main/webapp/WEB-INF/shiro.ini
index 21defe1..dd1d115 100644
--- a/server/src/main/webapp/WEB-INF/shiro.ini
+++ b/server/src/main/webapp/WEB-INF/shiro.ini
@@ -24,13 +24,6 @@ sessionManager = org.apache.shiro.web.session.mgt.DefaultWebSessionManager
 # Use the configured native session manager
 securityManager.sessionManager = $sessionManager
 
-jdbcRealm=com.ning.billing.server.security.KillbillJdbcRealm
-
 [urls]
-# Special endpoints: healthcheck, tenant API.
-# TODO: don't secure them for now - eventually require admin privileges
-/1.0/healthcheck = anon
-/1.0/kb/tenants/** = anon
-# For all other resources, require basic auth
-# TODO: ssl, authcBasic
-/1.0/kb/** = authcBasic
+# RBAC disabled by default
+/** = anon