Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-7816

The GetAclServlet and GetEffectiveAclServlet components should be only mapped to the json extension

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • JCR Jackrabbit Access Manager 3.0.0
    • None
    • None

    Description

      The GetAclServlet and GetEffectiveAclServlet are missing the "sling.servlet.extensions=json" property which means that those servlets may get unintentionally mapped to other (non-json) file extensions.

      This defect can prevent the developer from providing a custom libs/sling/servlet/default/acl.html script to provide an HTML view of the acl of a JCR node.

      For example, without the missing "sling.servlet.extensions=json" property, a request to /node.acl.html may return the json response instead of the expected response from the acl.html script.

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            enorman Eric Norman
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: