Uploaded image for project: 'Struts 2'
  1. Struts 2
  2. WW-4771

minor typos in confluence page "security.html"

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Trivial
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.5.12
    • Component/s: Documentation
    • Labels:

      Description

      • page : https://struts.apache.org/docs/security.html
      • spotted typos:
        • inside a title
          current
          Do not defined setters when not needed
          
          fixed
          Do not define setters when not needed
          
        • inside text under title Do not use incoming values as an input for localisation logic
          current
          All TextProvider's getText(...) methods (e.g in ActionSupport) performs evaluation of parameters included in a message to properly localize the text. This means using incoming request parameters with getText(...) methods is potentially dangerous and should be avoided. Se example below, assuming that an action implements getter and setter for property message, the below code allows inject an OGNL expression:
          
          fixed
          All TextProvider's getText(...) methods (e.g in ActionSupport) perform evaluation of parameters included in a message to properly localize the text. This means using incoming request parameters with getText(...) methods is potentially dangerous and should be avoided. See example below, assuming that an action implements getter and setter for property message, the below code allows inject an OGNL expression:
          
        • inside text under title Accepted / Excluded patterns
          current
          ...to check if param can accepted or must be excluded.
          
          fixed
          ...to check if param can be accepted or must be excluded.
          

        Activity

        Hide
        sdutry Stefaan Dutry added a comment -

        Wiki page edited.

        Issue resolved.

        Show
        sdutry Stefaan Dutry added a comment - Wiki page edited. Issue resolved.
        Hide
        sdutry Stefaan Dutry added a comment -

        Lukasz Lenart
        Am i missing something here?

        I'm pretty sure i edited and saved the page, but the changes seem to have been undone.

        Is this page autogenerated so that i need to edit the source it's being generated from?

        Show
        sdutry Stefaan Dutry added a comment - Lukasz Lenart Am i missing something here? I'm pretty sure i edited and saved the page, but the changes seem to have been undone. Is this page autogenerated so that i need to edit the source it's being generated from?
        Hide
        lukaszlenart Lukasz Lenart added a comment -

        I think it's ok https://cwiki.apache.org/confluence/pages/viewpreviousversions.action?pageId=34024409

        I must export the pages and put them on production - a bit manually process

        Show
        lukaszlenart Lukasz Lenart added a comment - I think it's ok https://cwiki.apache.org/confluence/pages/viewpreviousversions.action?pageId=34024409 I must export the pages and put them on production - a bit manually process
        Hide
        lukaszlenart Lukasz Lenart added a comment -

        That's why I want to move away from Confluence and use Markdown

        Show
        lukaszlenart Lukasz Lenart added a comment - That's why I want to move away from Confluence and use Markdown
        Hide
        lukaszlenart Lukasz Lenart added a comment -

        Done

        Show
        lukaszlenart Lukasz Lenart added a comment - Done
        Hide
        sdutry Stefaan Dutry added a comment -

        Thanks (and sorry for the manual work i caused )

        That's why I want to move away from Confluence and use Markdown

        Any developments on that side? (I don't see any additional .md files in the struts-site project yet)
        Like previously stated, i wouldn't mind helping with migrating documentation.

        Show
        sdutry Stefaan Dutry added a comment - Thanks (and sorry for the manual work i caused ) That's why I want to move away from Confluence and use Markdown Any developments on that side? (I don't see any additional .md files in the struts-site project yet) Like previously stated, i wouldn't mind helping with migrating documentation.
        Hide
        lukaszlenart Lukasz Lenart added a comment -

        Nothing to worry about and yes I'm going to start porting the existing Getting Started guide as soon I will handle all the security mess related to the Multipart parsers

        Show
        lukaszlenart Lukasz Lenart added a comment - Nothing to worry about and yes I'm going to start porting the existing Getting Started guide as soon I will handle all the security mess related to the Multipart parsers

          People

          • Assignee:
            Unassigned
            Reporter:
            sdutry Stefaan Dutry
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development