Frank Kobzik has posted comments on this change.

Change subject: frontend: Non-plugin automatic invocation of console session
......................................................................


Patch Set 4: (1 inline comment)

....................................................
File 
frontend/webadmin/modules/gwt-common/src/main/java/org/ovirt/engine/ui/common/uicommon/SpiceNativeImpl.java
Line 21: 
Line 22:         
configBuilder.append(lineSeparator).append("type=spice")//$NON-NLS-1$
Line 23:             
.append(lineSeparator).append("host=").append(getHost())//$NON-NLS-1$
Line 24:             
.append(lineSeparator).append("password=").append(getPassword())//$NON-NLS-1$
Line 25:             
.append(lineSeparator).append("port=").append(Integer.toString(getPort()));//$NON-NLS-1$
But this is not safe. If e.g. getPassword() contains "@PORT@" substring, this 
would be substituted by replace(...) in the following step. This could seem 
superlative at the moment, but I can imagine this could cause problems when 
more things are added to the string. It would be better to avoid this.
Line 26: 
Line 27:         
ConsoleModel.makeConsoleConfigRequest(configBuilder.toString());
Line 28:     }
Line 29: 


--
To view, visit http://gerrit.ovirt.org/11703
To unsubscribe, visit http://gerrit.ovirt.org/settings

Gerrit-MessageType: comment
Gerrit-Change-Id: Ib31e870deb7ecb3dac4cff25e49a3ebca4706a25
Gerrit-PatchSet: 4
Gerrit-Project: ovirt-engine
Gerrit-Branch: master
Gerrit-Owner: Frank Kobzik <[email protected]>
Gerrit-Reviewer: Alon Bar-Lev <[email protected]>
Gerrit-Reviewer: Frank Kobzik <[email protected]>
Gerrit-Reviewer: Juan Hernandez <[email protected]>
Gerrit-Reviewer: Tomas Jelinek <[email protected]>
Gerrit-Reviewer: Vojtech Szocs <[email protected]>
_______________________________________________
Engine-patches mailing list
[email protected]
http://lists.ovirt.org/mailman/listinfo/engine-patches

Reply via email to