Uploaded image for project: 'Hue (READ ONLY)'
  1. Hue (READ ONLY)
  2. HUE-4813

[core] Disable collecting referrer URL in Google Analytics

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 3.9.0, 3.10.0, 3.11.0
    • Fix Version/s: 3.12.0
    • Component/s: core.users, tools
    • Labels:
      None

      Description

      Google Analytics tracking should be turned off by default in open source distribution of Hue.

      Currently, even if collect_usage is commented out in the hue.ini (as shipped), the default for collect_usage is set to true. A user/administrator who may not be aware of this default, or who doesn't even have this config var in their hue.ini, may be sending analytics data to Google without knowing it.

      While only anonymous tracking data may be collected from the Hue source, the referrer URL is collected by Google and this can represent a significant security hole for some organizations. The referrer URL, especially in the case of the File Browser, can contain the HDFS path, which may contain proprietary information. Users or administrators of Hue may not be aware that Google is receiving the referrer URL, and as such may not be aware that tracking from the File Browser in particular is sending HDFS paths to Google.

        Attachments

          Activity

            People

            • Assignee:
              enricoberti Enrico Berti
              Reporter:
              rbernota Rick Bernotas
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: