Uploaded image for project: 'JSPWiki'
  1. JSPWiki
  2. JSPWIKI-331

Security error on JSPWiki.jar

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Invalid
    • 2.6.3
    • None
    • None
    • glassfish. linux.

    Description

      Log file shows many of the following messages. When this occurs, there is a large delay in time before the request is completed, upwards of 5 seconds:

      [#|2008-08-02T19:00:47.255-0500|INFO|sun-appserver9.1|javax.enterprise.system.core.security|_ThreadID=22;_ThreadName=httpSSLWorkerThread-443-8;|JACC Policy Provider: PolicyWrapper.implies,context(ewiki/ewiki)- permission(("com.ecyrd.jspwiki.auth.permissions.AllPermission","JSPWiki")) domain that failed(ProtectionDomain  (file:/opt/ewiki/WEB-INF/lib/JSPWiki.jar <no signer certificates>)
       WebappClassLoader
        delegate: true
        repositories:
          /WEB-INF/classes/
      ----------> Parent Classloader:
      EJBClassLoader :
      urlSet = []
      doneCalled = false
       Parent -> java.net.URLClassLoader@1fc3c84
      
      
       (principals com.ecyrd.jspwiki.auth.login.PrincipalWrapper "clay@izones.net",
      com.ecyrd.jspwiki.auth.authorize.Role "Authenticated",
      com.ecyrd.jspwiki.auth.authorize.Role "All",
      com.ecyrd.jspwiki.auth.authorize.Role "Admin")
      
       java.security.Permissions@3a018a (
       (javax.management.MBeanPermission [com.sun.messaging.jms.*:*] *)
       (java.net.SocketPermission localhost:1024- listen,resolve)
       (java.net.SocketPermission * connect,resolve)
       (java.net.SocketPermission * connect,resolve)
       (javax.security.auth.PrivateCredentialPermission javax.resource.spi.security.PasswordCredential * "*" read)
       (unresolved javax.security.jacc.WebUserDataPermission /Upload.jsp DELETE,GET,HEAD,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /Login.jsp DELETE,GET,HEAD,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /Comment.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /Edit.jsp DELETE,GET,HEAD,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /Rename.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /NewGroup.jsp DELETE,GET,HEAD,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /Rename.jsp DELETE,GET,HEAD,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /Edit.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /NewGroup.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /Upload.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /Comment.jsp DELETE,GET,HEAD,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /attach !DELETE,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /Login.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebUserDataPermission /*:/Delete.jsp:/Comment.jsp:/Rename.jsp:/NewGroup.jsp:/Edit.jsp:/Upload.jsp:/Login.jsp:/attach:/images/* :CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /attach DELETE,POST,PUT:CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /images/* :CONFIDENTIAL)
       (unresolved javax.security.jacc.WebUserDataPermission /Delete.jsp :CONFIDENTIAL)
       (unresolved com.sun.corba.ee.impl.presentation.rmi.DynamicAccessPermission access null)
       (unresolved com.sun.corba.ee.impl.presentation.rmi.DynamicAccessPermission access null)
       (unresolved javax.security.jacc.WebResourcePermission /NewGroup.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebResourcePermission /images/* null)
       (unresolved javax.security.jacc.WebResourcePermission /Comment.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebResourcePermission /Rename.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebResourcePermission /attach !DELETE,POST,PUT)
       (unresolved javax.security.jacc.WebResourcePermission /Upload.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebResourcePermission /Login.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved javax.security.jacc.WebResourcePermission /Edit.jsp !DELETE,GET,HEAD,POST,PUT)
       (unresolved com.sun.enterprise.security.CORBAObjectPermission * *)
       (unresolved com.sun.enterprise.security.CORBAObjectPermission * *)
       (java.lang.RuntimePermission getClassLoader)
       (java.lang.RuntimePermission loadLibrary.*)
       (java.lang.RuntimePermission accessDeclaredMembers)
       (java.lang.RuntimePermission getProtectionDomain)
       (java.lang.RuntimePermission modifyThreadGroup)
       (java.lang.RuntimePermission stopThread)
       (java.lang.RuntimePermission setContextClassLoader)
       (java.lang.RuntimePermission queuePrintJob)
       (javax.management.MBeanTrustPermission register)
       (java.io.FilePermission /tmp/- delete)
       (java.io.FilePermission /opt/glassfishv2ur1b09d/domains/domain1/lib/databases/- delete)
       (java.io.FilePermission <<ALL FILES>> read,write)
       (java.io.FilePermission /tmp/- delete)
       (java.io.FilePermission /opt/glassfishv2ur1b09d/domains/domain1/lib/databases/- delete)
       (java.io.FilePermission <<ALL FILES>> read,write)
       (java.io.FilePermission /opt/ewiki/WEB-INF/lib/JSPWiki.jar read)
       (java.util.PropertyPermission line.separator read)
       (java.util.PropertyPermission java.vm.version read)
       (java.util.PropertyPermission java.vm.specification.version read)
       (java.util.PropertyPermission java.vm.specification.vendor read)
       (java.util.PropertyPermission java.vendor.url read)
       (java.util.PropertyPermission java.vm.name read)
       (java.util.PropertyPermission * read,write)
       (java.util.PropertyPermission os.name read)
       (java.util.PropertyPermission java.vm.vendor read)
       (java.util.PropertyPermission path.separator read)
       (java.util.PropertyPermission java.specification.name read)
       (java.util.PropertyPermission os.version read)
       (java.util.PropertyPermission os.arch read)
       (java.util.PropertyPermission java.class.version read)
       (java.util.PropertyPermission java.version read)
       (java.util.PropertyPermission file.separator read)
       (java.util.PropertyPermission java.vendor read)
       (java.util.PropertyPermission java.vm.specification.name read)
       (java.util.PropertyPermission java.specification.version read)
       (java.util.PropertyPermission java.specification.vendor read)
      )
      
      )|#]
      

      Attachments

        Activity

          People

            metskem Harry Metske
            spoticus1000 Clay Atkins
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: