[ 
https://issues.apache.org/jira/browse/SLING-2433?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13231622#comment-13231622
 ] 

Eric Norman commented on SLING-2433:
------------------------------------

I would vote against doing this.  Allowing the user to upload an untrusted xsl 
stylesheet and do the transformation on the server introduces lots of nasty 
security problems.


                
> Add xml-stylesheet support to XML :import POST operation
> --------------------------------------------------------
>
>                 Key: SLING-2433
>                 URL: https://issues.apache.org/jira/browse/SLING-2433
>             Project: Sling
>          Issue Type: Improvement
>          Components: JCR, Servlets
>    Affects Versions: Servlets Post 2.1.0, JCR ContentLoader 2.1.4
>         Environment: CQ 5.5
>            Reporter: Mike Pfaff
>            Priority: Minor
>
> It would be nice if one could also POST an XSL file for an XML :import 
> operation, so that the XML file is transformed before the import. This would 
> help a lot when one needs to import a custom(= non-JCR-view) XML file 

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to