[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-06-27 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14045861#comment-14045861 ] Hudson commented on WW-4146: SUCCESS: Integrated in Struts-JDK6-features #65 (See [https://build

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-06-27 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14045831#comment-14045831 ] ASF subversion and git services commented on WW-4146: - Commit 63de7730ee2

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-06-18 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14035483#comment-14035483 ] Hudson commented on WW-4146: SUCCESS: Integrated in Struts-JDK6-develop #50 (See [https://builds

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-06-18 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14035221#comment-14035221 ] ASF GitHub Bot commented on WW-4146: Github user asfgit closed the pull request at:

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-06-18 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14035217#comment-14035217 ] ASF subversion and git services commented on WW-4146: - Commit 63de7730ee2

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-06-18 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14034986#comment-14034986 ] ASF GitHub Bot commented on WW-4146: Github user lukaszlenart commented on a diff in the

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-05-12 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13996079#comment-13996079 ] ASF GitHub Bot commented on WW-4146: Github user emeroad commented on the pull request:

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-05-12 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13996077#comment-13996077 ] ASF GitHub Bot commented on WW-4146: GitHub user emeroad opened a pull request: http

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-04-06 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13961501#comment-13961501 ] Hudson commented on WW-4146: SUCCESS: Integrated in Struts-JDK6-features #41 (See [https://build

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-04-06 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13961428#comment-13961428 ] Hudson commented on WW-4146: ABORTED: Integrated in Struts-JDK6-master #893 (See [https://builds

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-03-27 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13950024#comment-13950024 ] Hudson commented on WW-4146: SUCCESS: Integrated in Struts-JDK6-develop #31 (See [https://builds

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-03-27 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13949766#comment-13949766 ] ASF subversion and git services commented on WW-4146: - Commit 86813c1a721

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-03-27 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13949717#comment-13949717 ] Lukasz Lenart commented on WW-4146: --- One issue, I assume it was committed by mistake: {code

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2014-03-08 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13924767#comment-13924767 ] Lukasz Lenart commented on WW-4146: --- I'm going to apply the patch to be included in 2.3.17

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-25 Thread bruce liu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13720361#comment-13720361 ] bruce liu commented on WW-4146: --- i think [~maurizio.cucchiara]'s patch will work and that maybe

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-25 Thread zhouyanming (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13719380#comment-13719380 ] zhouyanming commented on WW-4146: - I mean cache expression for map has no sense when foo.bar

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-25 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13719339#comment-13719339 ] Maurizio Cucchiara commented on WW-4146: {quote} can you determine foo if it is a has

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-25 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13719334#comment-13719334 ] Maurizio Cucchiara commented on WW-4146: [~coderbee] did you see my patch?

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread bruce liu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13719235#comment-13719235 ] bruce liu commented on WW-4146: --- to [Maurizio Cucchiara], i said "once i used LRUMap in an CTI

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread zhouyanming (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13719062#comment-13719062 ] zhouyanming commented on WW-4146: - {quote} Unfortunately my patch does not totally cover all

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718501#comment-13718501 ] Maurizio Cucchiara commented on WW-4146: {quote} it cause LRUMap swap frequently, res

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718492#comment-13718492 ] Maurizio Cucchiara commented on WW-4146: {quote} And I'd rather stick with some ASF s

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718490#comment-13718490 ] Maurizio Cucchiara commented on WW-4146: Unfortunately my patch does not totally cove

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718478#comment-13718478 ] Maurizio Cucchiara commented on WW-4146: Hi Bruce, I'm sorry, but I think that your s

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread bruce liu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718454#comment-13718454 ] bruce liu commented on WW-4146: --- i don't agree that it will reverse the whole architecture of S

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718456#comment-13718456 ] Maurizio Cucchiara commented on WW-4146: {quote} To avoid DOS users should rather use

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718406#comment-13718406 ] Maurizio Cucchiara commented on WW-4146: {quote} DOS attack could be valid expression

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718363#comment-13718363 ] Lukasz Lenart commented on WW-4146: --- To avoid DOS users should rather use Application Firew

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread zhouyanming (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718340#comment-13718340 ] zhouyanming commented on WW-4146: - DOS attack could be valid expression,the point is don't ca

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-24 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718186#comment-13718186 ] Maurizio Cucchiara commented on WW-4146: -1 It reverses the whole architecture of Str

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-23 Thread zhouyanming (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13718002#comment-13718002 ] zhouyanming commented on WW-4146: - agree with bruce liu > cache attack at O

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-23 Thread bruce liu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13717946#comment-13717946 ] bruce liu commented on WW-4146: --- I think, maybe the point is what parameter should put into cac

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Philip Luppens (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713573#comment-13713573 ] Philip Luppens commented on WW-4146: Exactly, I don't think disabling this cache will do

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713533#comment-13713533 ] Lukasz Lenart commented on WW-4146: --- Hm... but thus will slow down processing of request fo

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713509#comment-13713509 ] Maurizio Cucchiara commented on WW-4146: So, the Commons implementation doesn't sound

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread bruce liu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713503#comment-13713503 ] bruce liu commented on WW-4146: --- [~maurizio.cucchiara], yes, OgnlUtils is shared between diffe

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread bruce liu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713496#comment-13713496 ] bruce liu commented on WW-4146: --- yes, this is my first issue commit, i really didn't experience

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713492#comment-13713492 ] Maurizio Cucchiara commented on WW-4146: I don't know what is the purpose to choice a

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713481#comment-13713481 ] Lukasz Lenart commented on WW-4146: --- Maybe you are right. So switching to LRU is the best o

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713471#comment-13713471 ] Maurizio Cucchiara commented on WW-4146: OK, got it. But it seems to me that [~coderb

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713466#comment-13713466 ] Lukasz Lenart commented on WW-4146: --- [~maurizio.cucchiara] yes, but just to proof that the

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713453#comment-13713453 ] Maurizio Cucchiara commented on WW-4146: [~lukaszlenart], you are right, but you los

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Maurizio Cucchiara (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713442#comment-13713442 ] Maurizio Cucchiara commented on WW-4146: We can change the ConcurrentMap with an LRU

[jira] [Commented] (WW-4146) cache attack at OgnlUtil.expressions

2013-07-19 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4146?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13713443#comment-13713443 ] Lukasz Lenart commented on WW-4146: --- You can disable cache by setting: {code:xml} {code}