snoopdave commented on code in PR #161:
URL: https://github.com/apache/roller/pull/161#discussion_r4238468124
##########
app/pom.xml:
##########
@@ -529,11 +529,12 @@ limitations under the License.
</exclusions>
</dependency>
- <!-- todo: remove/replace propono -->
+ <!-- Used by Trackback; previously reached the classpath transitively
Review Comment:
🐞Claude Issue: **Blocking:** This adds `commons-httpclient:3.1` as a direct
compile dependency "for Trackback", but Trackback was removed on master
(#178/#163) and nothing in `app/src` imports `org.apache.commons.httpclient`
any more. `mvn dependency:tree` shows nothing else needs it. The library is EOL
and has known CVEs (CVE-2012-5783, CVE-2014-3577, CVE-2015-5262), so the WAR
would ship a vulnerable, unused jar that dependency scanners will flag. Remove
the whole `<dependency>` block, including its exclusions.
##########
app/src/main/java/org/apache/roller/weblogger/webservices/atomprotocol/MediaCollection.java:
##########
@@ -195,16 +180,16 @@ public Entry postMedia(AtomRequest areq, Entry entry)
throws AtomException {
}
}
throw new AtomException("Error saving media entry");
-
+
} catch (WebloggerException re) {
throw new AtomException("Posting media", re);
} catch (IOException ioe) {
throw new AtomException("Posting media", ioe);
}
}
-
-
- public Entry getEntry(AtomRequest areq) throws AtomException {
+
+
+ public AtomEntry getEntry(AtomRequest areq) throws AtomException {
Review Comment:
🐞Claude Issue: **Important:** `getEntry()` (GET on a `.media-link` URI) has
no permission check. Any authenticated user can read the media-link entry
(name, URLs, content type) of a file in any weblog, although `getCollection()`
in this class requires `canView` and `getMediaResource()` requires `canEdit`.
An unknown handle also gives `website == null`, which reaches
`getMediaFileByPath(null, ...)` and returns a 500. This was carried over from
the Propono version, but the rewrite is the moment to make it consistent:
return `AtomNotFoundException` when the weblog is missing and
`AtomNotAuthorizedException` when `!RollerAtomHandler.canView(user, website)`,
plus a test for each.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]