[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15654136#comment-15654136 ] ASF GitHub Bot commented on SLING-5135: --- Github user code-distillery closed the pull request at:

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread Julian Sedding (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653962#comment-15653962 ] Julian Sedding commented on SLING-5135: --- Fixed in revisions

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653778#comment-15653778 ] Bertrand Delacretaz commented on SLING-5135: Works for me, thanks! > Whitelist legit usages

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread Carsten Ziegeler (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653487#comment-15653487 ] Carsten Ziegeler commented on SLING-5135: - Sounds good to me, +1 for moving. The less api the

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread Julian Sedding (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653464#comment-15653464 ] Julian Sedding commented on SLING-5135: --- Thanks [~cziegeler] for your review. I was wondering

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread Carsten Ziegeler (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653438#comment-15653438 ] Carsten Ziegeler commented on SLING-5135: - [~jsedding] Thanks for taking this up, it looks good to

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-10 Thread Julian Sedding (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653406#comment-15653406 ] Julian Sedding commented on SLING-5135: --- SLING-5355 is useful for cutting down the

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread Julian Sedding (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653349#comment-15653349 ] Julian Sedding commented on SLING-5135: --- [~bdelacretaz], [~cziegeler] Could you take a look at the

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653334#comment-15653334 ] ASF GitHub Bot commented on SLING-5135: --- GitHub user code-distillery reopened a pull request:

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653321#comment-15653321 ] ASF GitHub Bot commented on SLING-5135: --- GitHub user code-distillery reopened a pull request:

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653325#comment-15653325 ] ASF GitHub Bot commented on SLING-5135: --- Github user code-distillery closed the pull request at:

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15653319#comment-15653319 ] ASF GitHub Bot commented on SLING-5135: --- Github user code-distillery closed the pull request at:

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread Julian Sedding (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15652007#comment-15652007 ] Julian Sedding commented on SLING-5135: --- I think the {{DefaultWhitelist}} can be reduced to the

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-09 Thread Carsten Ziegeler (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15651212#comment-15651212 ] Carsten Ziegeler commented on SLING-5135: - We should also check whether the default whitelist is

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-08 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15648163#comment-15648163 ] Bertrand Delacretaz commented on SLING-5135: You are correct about what's left to do. I

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-11-08 Thread Julian Sedding (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15647842#comment-15647842 ] Julian Sedding commented on SLING-5135: --- [~bdelacretaz] I will try to wrap this issue up, but I will

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-25 Thread Oliver Lietz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15604510#comment-15604510 ] Oliver Lietz commented on SLING-5135: - [~bdelacretaz]: can we align the property names making them

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-21 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15594738#comment-15594738 ] Bertrand Delacretaz commented on SLING-5135: I have modified the whitelisted BSNs config to

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-19 Thread Robert Munteanu (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15588073#comment-15588073 ] Robert Munteanu commented on SLING-5135: That sounds good to me. > Whitelist legit usages of

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-19 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15588070#comment-15588070 ] Bertrand Delacretaz commented on SLING-5135: bq. it would be useful to have a configuration

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-18 Thread Robert Munteanu (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15586647#comment-15586647 ] Robert Munteanu commented on SLING-5135: I think it would be useful to have a configuration option

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-12 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15568721#comment-15568721 ] Bertrand Delacretaz commented on SLING-5135: I have committed the launchpad changes in

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-11 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15565872#comment-15565872 ] Bertrand Delacretaz commented on SLING-5135: I have committed the bundles/ changes in revision

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-11 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15565525#comment-15565525 ] Bertrand Delacretaz commented on SLING-5135: The failing integration tests are caused by

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-10-10 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15562559#comment-15562559 ] Bertrand Delacretaz commented on SLING-5135: I now have an implementation at

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-09-07 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15470056#comment-15470056 ] Bertrand Delacretaz commented on SLING-5135: bq. ...I suppose calls to

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-09-06 Thread Antonio Sanso (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15467001#comment-15467001 ] Antonio Sanso commented on SLING-5135: -- bq. LoginAdminWhitelistImpl has a whitelist.bypass

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-09-06 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15466994#comment-15466994 ] Bertrand Delacretaz commented on SLING-5135: You're right that this might break some things in

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-09-05 Thread Antonio Sanso (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15466512#comment-15466512 ] Antonio Sanso commented on SLING-5135: -- [~bdelacretaz] LGTM. One little thing. I suspect that if we

[jira] [Commented] (SLING-5135) Whitelist legit usages of loginAdministrative and administrative ResourceResolver

2016-01-06 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/SLING-5135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15085551#comment-15085551 ] Bertrand Delacretaz commented on SLING-5135: The emerging idea from the dev list thread is to