Hi,

Ticket created:

https://osgeo-org.atlassian.net/browse/GEOS-7317

Thanks Andrea.

Regards,

Agur bero bat,



David Alda Fernández de Lezea
Área de Sistemas de Información Geográfica, Planificación Territorial y 
Forestal Informazio Geografikoen Sistemak, Lurralde eta Baso Antolaketaren 
Arloa.
da...@hazi.eus | www.hazi.eus
T 945 003 240 – M 627 923 170 – F 945 003 290 
Hazi | Granja Modelo de Arkaute s/n | 01192 Arkaute – Araba
 
*********************  LEGE OHARRA   *******************   AVISOLEGAL   
*******************   DISCLAIMER   *****************************
Mezu hau pertsonala eta isilpekoa da eta baimenik gabeko erabilera debekatua 
dago legalki. Jasotzailea ez bazara ezabatu mezua, bidali eta kontserbatu gabe.
Este mensaje es personal y confidencial y su uso no autorizado está prohibido 
legalmente. Si usted no es el destinatario, proceda a borrarlo, sin reenviarlo 
ni conservarlo.
This message is personal and confidential, unauthorised use is legally 
prohibited. If you are not the intended recipient, delete it without resending 
or backing it.

De: andrea.a...@gmail.com [mailto:andrea.a...@gmail.com] En nombre de Andrea 
Aime
Enviado el: miércoles, 18 de noviembre de 2015 10:59
Para: David Alda Fernandez de Lezea
CC: GeoServer Users
Asunto: Re: [Geoserver-users] GeoServer Migration Plan

Hi David,
nope, no clue as to why you're hitting that class, the XML seems "normal".
But I guess it does not hurt adding it to the whitelist.
Can you open a ticket at https://osgeo-org.atlassian.net/projects/GEOS/summary 
with
the stack trace above?

Cheers
Andrea


On Mon, Nov 16, 2015 at 9:19 AM, David Alda Fernandez de Lezea <da...@hazi.eus> 
wrote:
Hi Andrea,

Thanks for your response. Here's what's inside the xml files:

Layer.xml

<layer>
  <name>ForriskAlturaMediaEtrs89</name>
  <id>LayerInfoImpl-3f30cbbb:14d7ae3d4ba:-6323</id>
  <type>VECTOR</type>
  <defaultStyle>
    <id>StyleInfoImpl-4e0b98bf:12475d46fdd:-7fe0</id>
  </defaultStyle>
  <styles class="linked-hash-set">
    <style>
      <id>StyleInfoImpl-38e82ce1:14cd58a4153:-75bf</id>
    </style>
  </styles>
  <resource class="featureType">
    <id>FeatureTypeInfoImpl-3f30cbbb:14d7ae3d4ba:-6324</id>
  </resource>
  <attribution>
    <logoWidth>0</logoWidth>
    <logoHeight>0</logoHeight>
  </attribution>
</layer>


Featuretype.xml

<featureType>
  <id>FeatureTypeInfoImpl-3f30cbbb:14d7ae3d4ba:-6324</id>
  <name>ForriskAlturaMediaEtrs89</name>
  <nativeName>TB_RIESGO_INC_VIENTO_ET89</nativeName>
  <namespace>
    <id>NamespaceInfoImpl-2828037a:14d74b05c20:-775b</id>
  </namespace>
  <title>Forrisk - Altura Media (m)</title>
  <abstract>TB_RIESGO_INC_VIENTO_ET89</abstract>
  <nativeCRS class="projected">PROJCS[&quot;UTM Zone 30, (ETRS 89)&quot;, &#xd;
  GEOGCS[&quot;ETRS 89&quot;, &#xd;
    DATUM[&quot;ETRS 89&quot;, &#xd;
      SPHEROID[&quot;GRS 80&quot;, 6378137.0, 298.257222100883]], &#xd;
    PRIMEM[&quot;Greenwich&quot;, 0.0], &#xd;
    UNIT[&quot;degree&quot;, 0.017453292519943295], &#xd;
    AXIS[&quot;Longitude&quot;, EAST], &#xd;
    AXIS[&quot;Latitude&quot;, NORTH]], &#xd;
  PROJECTION[&quot;Transverse_Mercator&quot;], &#xd;
  PARAMETER[&quot;central_meridian&quot;, -3.0], &#xd;
  PARAMETER[&quot;latitude_of_origin&quot;, 0.0], &#xd;
  PARAMETER[&quot;scale_factor&quot;, 0.9996], &#xd;
  PARAMETER[&quot;false_easting&quot;, 500000.0], &#xd;
  PARAMETER[&quot;false_northing&quot;, 0.0], &#xd;
  UNIT[&quot;m&quot;, 1.0], &#xd;
  AXIS[&quot;x&quot;, EAST], &#xd;
  AXIS[&quot;y&quot;, NORTH]]</nativeCRS>
  <srs>EPSG:25830</srs>
  <nativeBoundingBox>
    <minx>463435.23</minx>
    <maxx>603054.68</maxx>
    <miny>4702205.332</miny>
    <maxy>4811327.358</maxy>
  </nativeBoundingBox>
  <latLonBoundingBox>
    <minx>-3.452</minx>
    <maxx>-1.726</maxx>
    <miny>42.465</miny>
    <maxy>43.455</maxy>
    <crs>EPSG:4326</crs>
  </latLonBoundingBox>
  <projectionPolicy>FORCE_DECLARED</projectionPolicy>
  <enabled>true</enabled>
  <metadata>
    <entry key="cachingEnabled">false</entry>
  </metadata>
  <store class="dataStore">
    <id>DataStoreInfoImpl-2828037a:14d74b05c20:-775a</id>
  </store>
  <maxFeatures>0</maxFeatures>
  <numDecimals>0</numDecimals>
  <overridingServiceSRS>false</overridingServiceSRS>
  <skipNumberMatched>false</skipNumberMatched>
  <circularArcPresent>false</circularArcPresent>
</featureType>


Regards,


Agur bero bat,



David Alda Fernández de Lezea
Área de Sistemas de Información Geográfica, Planificación Territorial y 
Forestal Informazio Geografikoen Sistemak, Lurralde eta Baso Antolaketaren 
Arloa.
da...@hazi.eus | www.hazi.eus
T 945 003 240 – M 627 923 170 – F 945 003 290
Hazi | Granja Modelo de Arkaute s/n | 01192 Arkaute – Araba
 
*********************  LEGE OHARRA   *******************   AVISOLEGAL   
*******************   DISCLAIMER   *****************************
Mezu hau pertsonala eta isilpekoa da eta baimenik gabeko erabilera debekatua 
dago legalki. Jasotzailea ez bazara ezabatu mezua, bidali eta kontserbatu gabe.
Este mensaje es personal y confidencial y su uso no autorizado está prohibido 
legalmente. Si usted no es el destinatario, proceda a borrarlo, sin reenviarlo 
ni conservarlo.
This message is personal and confidential, unauthorised use is legally 
prohibited. If you are not the intended recipient, delete it without resending 
or backing it.

De: andrea.a...@gmail.com [mailto:andrea.a...@gmail.com] En nombre de Andrea 
Aime
Enviado el: sábado, 14 de noviembre de 2015 14:01
Para: David Alda Fernandez de Lezea
CC: GeoServer Users
Asunto: Re: [Geoserver-users] GeoServer Migration Plan
On Wed, Nov 11, 2015 at 11:21 AM, David Alda Fernandez de Lezea 
<da...@hazi.eus> wrote:
11 Nov 11:14:46 WARN [org.geoserver] - Failed to load layer for feature type 
'ForriskAlturaMediaEtrs89'
com.thoughtworks.xstream.converters.ConversionException: Unauthorized class 
found, see logs for more details on how to handle it: 
com.thoughtworks.xstream.mapper.DynamicProxyMapper$DynamicProxy : Unauthorized 
class found, see logs for more details on how to handle it: 
com.thoughtworks.xstream.mapper.DynamicProxyMapper$DynamicProxy

This one is a side effect of our hardening against remote execution attacks, 
which allowed people with
access to the REST api (admins) to launch a random executable on the machine 
running GeoServer.
We basically had to provide a white-list of files that can be de-serialized 
from XML.

This one, com.thoughtworks.xstream.mapper.DynamicProxyMapper$DynamicProxy, is 
new and unexpected.
Can you share what's in the ForriskAlturaMediaEtrs89 configuration files? 
It will be in a path like:

<geoserverDataDir>/workspaces/<theLayerWorkspace>/<theLayerStore>/ForriskAlturaMediaEtrs89/*.xml

Cheers
Andrea

--
==
GeoServer Professional Services from the experts! Visit
http://goo.gl/it488V for more information.
==

Ing. Andrea Aime 
@geowolf
Technical Lead

GeoSolutions S.A.S.
Via Poggio alle Viti 1187
55054  Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39  339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o nel/i 
file/s allegato/i sono da considerarsi strettamente riservate. Il loro utilizzo 
è consentito esclusivamente al destinatario del messaggio, per le finalità 
indicate nel messaggio stesso. Qualora riceviate questo messaggio senza esserne 
il destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di 
procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro 
sistema. Conservare il messaggio stesso, divulgarlo anche in parte, 
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità diverse, 
costituisce comportamento contrario ai principi dettati dal D.Lgs. 196/2003.
 
The information in this message and/or attachments, is intended solely for the 
attention and use of the named addressee(s) and may be confidential or 
proprietary in nature or covered by the provisions of privacy act (Legislative 
Decree June, 30 2003, no.196 - Italy's New Data Protection Code).Any use not in 
accord with its purpose, any disclosure, reproduction, copying, distribution, 
or either dissemination, either whole or partial, is strictly forbidden except 
previous formal approval of the named addressee(s). If you are not the intended 
recipient, please contact immediately the sender by telephone, fax or e-mail 
and delete the information in this message that has been received in error. The 
sender does not give any warranty or accept liability as the content, accuracy 
or completeness of sent messages and accepts no responsibility  for changes 
made after they were sent or for other risks which arise as a result of e-mail 
transmission, viruses, etc.

-------------------------------------------------------




-- 
==
GeoServer Professional Services from the experts! Visit
http://goo.gl/it488V for more information.
==

Ing. Andrea Aime 
@geowolf
Technical Lead

GeoSolutions S.A.S.
Via Poggio alle Viti 1187
55054  Massarosa (LU)
Italy
phone: +39 0584 962313
fax: +39 0584 1660272
mob: +39  339 8844549

http://www.geo-solutions.it
http://twitter.com/geosolutions_it

AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
Le informazioni contenute in questo messaggio di posta elettronica e/o nel/i 
file/s allegato/i sono da considerarsi strettamente riservate. Il loro utilizzo 
è consentito esclusivamente al destinatario del messaggio, per le finalità 
indicate nel messaggio stesso. Qualora riceviate questo messaggio senza esserne 
il destinatario, Vi preghiamo cortesemente di darcene notizia via e-mail e di 
procedere alla distruzione del messaggio stesso, cancellandolo dal Vostro 
sistema. Conservare il messaggio stesso, divulgarlo anche in parte, 
distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità diverse, 
costituisce comportamento contrario ai principi dettati dal D.Lgs. 196/2003.
 
The information in this message and/or attachments, is intended solely for the 
attention and use of the named addressee(s) and may be confidential or 
proprietary in nature or covered by the provisions of privacy act (Legislative 
Decree June, 30 2003, no.196 - Italy's New Data Protection Code).Any use not in 
accord with its purpose, any disclosure, reproduction, copying, distribution, 
or either dissemination, either whole or partial, is strictly forbidden except 
previous formal approval of the named addressee(s). If you are not the intended 
recipient, please contact immediately the sender by telephone, fax or e-mail 
and delete the information in this message that has been received in error. The 
sender does not give any warranty or accept liability as the content, accuracy 
or completeness of sent messages and accepts no responsibility  for changes 
made after they were sent or for other risks which arise as a result of e-mail 
transmission, viruses, etc.

-------------------------------------------------------
------------------------------------------------------------------------------
_______________________________________________
Geoserver-users mailing list
Geoserver-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/geoserver-users

Reply via email to