[xwiki-users] Xwiki LDAP Configuration - multiple LDAP Base question

2012-11-20 Thread Csaba
Hi, I would like to configure the XWIKI LDAP and I encountered a specific issue defining more than one base_DN. Is this possible at all? I have 2 types of Users: 1. o=org1, c=c1, dc=company 2. o=org2, c=c2, dc=company These Users also have a common Group:

[xwiki-users] Security check on RSS Aggregator Macro extension

2012-11-20 Thread Fernando Correia
One comment in the blog post[1] about the RSS Aggregator Macro[2] warns against a serious security flaw: the extension is embedding in the page's wiki markup strings it reads from the web (RSS feeds); if these strings contain wiki code such as this: titleLet's execute some groovy:

Re: [xwiki-users] Security check on RSS Aggregator Macro extension

2012-11-20 Thread Jerome Velociter
Hi Fernando, Actually, I've fixed the issue just after reading xipe's comment back in 2009, by enclosing everything the macro outputs in {{{verbatim markup}}}. See the update line at the top of the blog post. This was even before XWiki prevented nested scripting by default. Could you edit

Re: [xwiki-users] Security check on RSS Aggregator Macro extension

2012-11-20 Thread Fernando Correia
Hi Jerome, thanks for the quick answer! My bad, I didn't notice the {{{ thing (so many symbols on that line...) It's great to know that flaw has long been fixed. I've already updated my comment and your extension is being very useful for us because we couldn't make the built-in rss extension to