[
https://issues.apache.org/jira/browse/SLING-13339?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Joerg Hoh updated SLING-13339:
------------------------------
Description:
Certain failures during a sanitizer policy reload were not correctly handled.
Under specific conditions, this could leave the sanitizer without a valid
policy in place, without falling back to a safe default.
h5. Details
* Policy reload failure leaves activePolicy null, no embedded fallback
Commit:
https://github.com/apache/sling-org-apache-sling-xss/commit/2991c35f654814ce216cb3f07078e4dedda07166
was:
Certain failures during a sanitizer policy reload were not correctly handled.
Under specific conditions, this could leave the sanitizer without a valid
policy in place, without falling back to a safe default.
Commit:
https://github.com/apache/sling-org-apache-sling-xss/commit/2991c35f654814ce216cb3f07078e4dedda07166
> Sanitizer policy reload failure could leave sanitizer in a degraded state
> -------------------------------------------------------------------------
>
> Key: SLING-13339
> URL: https://issues.apache.org/jira/browse/SLING-13339
> Project: Sling
> Issue Type: Improvement
> Components: XSS Protection API
> Reporter: Joerg Hoh
> Assignee: Joerg Hoh
> Priority: Major
> Fix For: XSS Protection API 2.4.12
>
>
> Certain failures during a sanitizer policy reload were not correctly handled.
> Under specific conditions, this could leave the sanitizer without a valid
> policy in place, without falling back to a safe default.
> h5. Details
> * Policy reload failure leaves activePolicy null, no embedded fallback
> Commit:
> https://github.com/apache/sling-org-apache-sling-xss/commit/2991c35f654814ce216cb3f07078e4dedda07166
--
This message was sent by Atlassian Jira
(v8.20.10#820010)