ahgittin commented on issue #1044: Added default security config for XStream URL: https://github.com/apache/brooklyn-server/pull/1044#issuecomment-462824486 LGTM. Confirmed this is the only place we do `new XStream()`. In future we may make this configurable, but as we restrict so only privileged users can specify which classes can be put into places where they will be serialized (ie adding them to catalog) we already have the protection this constraint affords.
---------------------------------------------------------------- This is an automated message from the Apache Git Service. To respond to the message, please log on GitHub and use the URL above to go to the specific comment. For queries about this service, please contact Infrastructure at: [email protected] With regards, Apache Git Services
