Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
Description
Currently the default ESAPI policies are configured through a file from the repository - /libs/sling/xss/config.xml. However, the proposed XSSFilter API allows filtering using random policy files. The configuration should be performed only through the /libs/sling/xss/config.xml file, or through an /apps overlay.