Potential XSS-Vulnerability due to the way Wicket renders JavaScript in CDATA blocks?

2012-12-06 Thread spam2...@meeque.de
Hello List, I must admit, I don't follow here too closely. But I've searched the archive and Wicket's Jira, and have not found much discussion regarding this Issue. So let me elaborate... A partner pointed me to a XSS vulnerability in one of our websites built with Wicket. The respective page

Re: Proposal: TabbedPanel variant that does all the work on the client

2009-11-08 Thread spam2...@meeque.de
Thanks for the advice Mike! You should: 1. Get a sourceforge account. 2. Request on d...@wicket.apache.org to be given commit access to the wicketstuff repository. I think 'wicketstuff-minis' might be the most suitable place for your code since it is fairly small. [...] For now, I

Re: Proposal: TabbedPanel variant that does all the work on the client

2009-11-08 Thread spam2...@meeque.de
Hi Ernesto, Is your implementation using jQuery? Then maybe you should try to contact someone behind some of the jQuery-Wicket related projects out there and see if your component could feet on one of those projects. Yes, right now it's using jQuery. I'll have a look at jQuery-Wicket, and