Re: [basex-talk] SSL support for BaseX REST API

2018-03-14 Thread Andy Bunce
I have been trying this out recently, in part to look at service workers [1] I am using BaseX 9 betas for this. This has a newer jetty version. I have put a jetty.xml that is working for me as a gist [2] You will need to change the keystore location [3] to something that points to your keystore.

Re: [basex-talk] SSL support for BaseX REST API

2018-03-14 Thread Liam R. E. Quin
On Wed, 2018-03-14 at 14:18 -0500, Giavanna J Richards wrote: > I'm trying to determine how to enable SSL communications with the > BaseX server I don't know if this helps, but I run BaseX listening only to "localhost" so that SSL isn't an issue (as a connection to localhost doesn't normally go

Re: [basex-talk] TR: Marklogic XXE and XML Bomb prevention

2018-03-14 Thread Christian Grün
Bridger, thanks a lot for the good reminder! Bridger Dyson-Smith schrieb am Mi., 14. März 2018, 21:29: > Forwarding/replying to the list, since I'm officially Bad At Email. > > On Wed, Mar 14, 2018 at 11:56 AM, Bridger Dyson-Smith < > bdysonsm...@gmail.com> wrote: > >>

Re: [basex-talk] TR: Marklogic XXE and XML Bomb prevention

2018-03-14 Thread Bridger Dyson-Smith
Forwarding/replying to the list, since I'm officially Bad At Email. On Wed, Mar 14, 2018 at 11:56 AM, Bridger Dyson-Smith wrote: > Hi Fabrice - > > On Wed, Mar 14, 2018 at 11:28 AM, Fabrice ETANCHAUD < > fetanch...@pch.cerfrance.fr> wrote: > >> Hello, >> >> >> >> I found

Re: [basex-talk] SSL support for BaseX REST API

2018-03-14 Thread Christian Grün
Hi Giavanna, The SSL features has not been maintained anymore for a while now. With BaseX 9.0, it will be completely removed, because the old solution is not compatible anymore with Jetty 9. We may introduce it in future once we find a good way to do. There is a StackOverflow question that

Re: [basex-talk] TR: Marklogic XXE and XML Bomb prevention

2018-03-14 Thread Christian Grün
Hi Fabrice, Thanks for the hint; definitely interesting to track down. Did you already manage to trigger this behavior in BaseX (with the REST interface, or anything else)? Best, Christian On Wed, Mar 14, 2018 at 4:28 PM, Fabrice ETANCHAUD wrote: > Hello, > > > >

[basex-talk] SSL support for BaseX REST API

2018-03-14 Thread Giavanna J Richards
I'm trying to determine how to enable SSL communications with the BaseX server, I have a java server which communicates with BaseX over its REST API for running xquery's. I see in the BaseX changelog that SSL support was added to version 7.5 in 2012 but I haven't been able to find any

[basex-talk] TR: Marklogic XXE and XML Bomb prevention

2018-03-14 Thread Fabrice ETANCHAUD
Hello, I found this MarkLogic post interesting, So I forward it to the BaseX users. I do not remember loading data I did not trust, but did somebody experience this kind of issue ? Best regards, Fabrice Etanchaud De : general-boun...@developer.marklogic.com