Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
Description
The XSS Protection API should be enhanced to provide some reporting about invalid URLs in order to allow operators of a Sling instance to monitor the state of the system (e.g. incorrect AntiSamy configurations, attacks, DOS attempts, etc.).
The following ideas should be taken into consideration:
- add last X blocked expressions to the Sling XSS Web Console page
- generate blocked metrics, based on configurable paths, e.g. /libs, /apps, /content.
Attachments
Issue Links
- links to