Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-4492

Prevent configuring the ESAPI policies through random content files

    XMLWordPrintableJSON

Details

    Description

      Currently the default ESAPI policies are configured through a file from the repository - /libs/sling/xss/config.xml. However, the proposed XSSFilter API allows filtering using random policy files. The configuration should be performed only through the /libs/sling/xss/config.xml file, or through an /apps overlay.

      Attachments

        Activity

          People

            radu Radu Cotescu
            radu Radu Cotescu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: