Hi Edmore,

most string fields in Solr are escaped, which aparrently does not apply to the 
oc_creator field. This should definitely be considered a bug, so thanks for 
opening the ticket.

Tobias

On 05.07.2012, at 14:59, Edmore Moyo <[email protected]> wrote:

> Good day,
> 
> I recently noticed that when some solr queries are built up there is no 
> escaping of certain characters such as colons (:)  Strings are accepted as 
> is, which results in error.
> 
> http://opencast.jira.com/browse/MH-8924
> 
> Is there a recommended format for strings that are passed to these queries ? 
> Could accepting non-escaped strings, such as the lti string in the ticket I 
> have highlighted, not be a potential security flaw?
> 
> Regards,
> 
> Edmore Moyo
_______________________________________________
Matterhorn mailing list
[email protected]
http://lists.opencastproject.org/mailman/listinfo/matterhorn


To unsubscribe please email
[email protected]
_______________________________________________

Reply via email to