[ 
https://issues.apache.org/jira/browse/SLING-4492?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Radu Cotescu updated SLING-4492:
--------------------------------
    Description: Currently the default ESAPI policies are configured through a 
file from the repository - {{/libs/sling/xss/config.xml}}. However, the 
proposed {{XSSFilter}} API allows filtering using random policy files. The 
configuration should be performed only through the 
{{/libs/sling/xss/config.xml}} file, or through an {{/apps}} overlay.  (was: 
Currently the ESAPI policies are configured through a file from the repository 
- {{/libs/sling/xss/config.xml}}. However, the configuration of the XSS bundle 
should be made through OSGi mechanisms instead of relying on content structures 
and content overlay.

This issue tracks only the removal of the ESAPI configuration from the content.)

> Prevent configuring the ESAPI policies through random content files
> -------------------------------------------------------------------
>
>                 Key: SLING-4492
>                 URL: https://issues.apache.org/jira/browse/SLING-4492
>             Project: Sling
>          Issue Type: Bug
>          Components: Extensions
>            Reporter: Radu Cotescu
>            Assignee: Radu Cotescu
>             Fix For: XSS Protection API 1.0.0
>
>
> Currently the default ESAPI policies are configured through a file from the 
> repository - {{/libs/sling/xss/config.xml}}. However, the proposed 
> {{XSSFilter}} API allows filtering using random policy files. The 
> configuration should be performed only through the 
> {{/libs/sling/xss/config.xml}} file, or through an {{/apps}} overlay.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to