[ 
https://issues.apache.org/jira/browse/OFBIZ-12273?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17374103#comment-17374103
 ] 

ASF subversion and git services commented on OFBIZ-12273:
---------------------------------------------------------

Commit 0effce0c7b07483143b92e5c673cf8d55db6cef1 in ofbiz-framework's branch 
refs/heads/trunk from Jacques Le Roux
[ https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=0effce0 ]

Fixed: IndexOutOfBoundsException on Entity Import (OFBIZ-12273)

I get an IndexOutOfBoundsException when using the EntityImport.

The problem occurs while having a resemblance of an url in the data.
For example
screenPath="component://... is interpreted as url because of '://'
but doesn't match a valid url pattern.

jleroux: I decided to keep it simple and to take the "component://" and the
"https://localhost"; cases apart. I see no reasons to fear "https://localhost";
there. It should be only used in a safe dev env.

Thanks: Sebastian Berg and Nicolas Malin for report


> IndexOutOfBoundsException on Entity Import
> ------------------------------------------
>
>                 Key: OFBIZ-12273
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-12273
>             Project: OFBiz
>          Issue Type: Bug
>    Affects Versions: 18.12.01, Release Branch 17.12, Trunk
>            Reporter: Sebastian Berg
>            Assignee: Jacques Le Roux
>            Priority: Major
>
> I get an IndexOutOfBoundsException when using the EntityImport.
> The problem occurs while having a resemblance of an url in the data.
> For example '
> screenPath="component://project/widget/project/ContentScreens.xml#main-page-template"'
>  is interpreted as url because of '://' but doesn't match a valid url 
> pattern. 
> The problem seems to be directly connected to Issue 12249. I think the used 
> pattern in UtilHttp.exctractUrl() should at least be configureable like the 
> customSafePolicy. [~jleroux] maybe you can have a look since you implemented 
> the changes.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to