[ 
https://issues.apache.org/jira/browse/DELTASPIKE-752?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14185072#comment-14185072
 ] 

Gerhard Petracek commented on DELTASPIKE-752:
---------------------------------------------

@thomas:
i created DELTASPIKE-756

@heiko, mark and thomas:
i'm not sure if it makes sense to append the value to window.name since the 
value in window.name breaks anyway >if< you really need it as it is (for 
whatever reason) >and< ds adds something to it. you could just fix the issue by 
not using the script which drops that part of the window-handling. -> if the 
script is in place it can just override the value (if a changed value is an 
issue for the application, those users can't use the script anyway).

> ensure a secure maximum length of the window-id
> -----------------------------------------------
>
>                 Key: DELTASPIKE-752
>                 URL: https://issues.apache.org/jira/browse/DELTASPIKE-752
>             Project: DeltaSpike
>          Issue Type: Bug
>          Components: JSF-Module, JSF22-Module
>    Affects Versions: 1.0.3
>            Reporter: Heiko Kopp
>            Priority: Critical
>             Fix For: 1.0.4
>
>
> if the window-id is too long, we would need to escape it to avoid XSS.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to