Re: About "Parameter Validation Filter"

2018-03-01 Thread Lukasz Lenart
2018-02-28 17:55 GMT+01:00 Emi <em...@encs.concordia.ca>:
> Hello,
>
> There is a topic about Parameter Validation Filter (TrimTextValidationRule,
> FailIfNotCanonicalizedValidationRule, FailIfContainsHTMLValidationRule) for
> servlet (https://www.owasp.org/index.php/Parameter_Validation_Filter).
>
> I just want to know that struts2.5.14.1 already have these kinds of
> validation set by default and no need to add pvf.xml anymore, right?

No, I mean, Struts do not perform such validations automatically.


Regards
-- 
Ɓukasz
+ 48 606 323 122 http://www.lenart.org.pl/

-
To unsubscribe, e-mail: user-unsubscr...@struts.apache.org
For additional commands, e-mail: user-h...@struts.apache.org



About "Parameter Validation Filter"

2018-02-28 Thread Emi

Hello,

There is a topic about Parameter Validation Filter 
(TrimTextValidationRule, FailIfNotCanonicalizedValidationRule, 
FailIfContainsHTMLValidationRule) for servlet 
(https://www.owasp.org/index.php/Parameter_Validation_Filter).


I just want to know that struts2.5.14.1 already have these kinds of 
validation set by default and no need to add pvf.xml anymore, right?


Thanks a lot.