snoopdave commented on code in PR #161:
URL: https://github.com/apache/roller/pull/161#discussion_r4238468124


##########
app/pom.xml:
##########
@@ -529,11 +529,12 @@ limitations under the License.
             </exclusions>
         </dependency>
 
-        <!-- todo: remove/replace propono -->
+        <!-- Used by Trackback; previously reached the classpath transitively

Review Comment:
   🐞Claude Issue: **Blocking:** This adds `commons-httpclient:3.1` as a direct 
compile dependency "for Trackback", but Trackback was removed on master 
(#178/#163) and nothing in `app/src` imports `org.apache.commons.httpclient` 
any more. `mvn dependency:tree` shows nothing else needs it. The library is EOL 
and has known CVEs (CVE-2012-5783, CVE-2014-3577, CVE-2015-5262), so the WAR 
would ship a vulnerable, unused jar that dependency scanners will flag. Remove 
the whole `<dependency>` block, including its exclusions.



##########
app/src/main/java/org/apache/roller/weblogger/webservices/atomprotocol/MediaCollection.java:
##########
@@ -195,16 +180,16 @@ public Entry postMedia(AtomRequest areq, Entry entry) 
throws AtomException {
                 }
             }
             throw new AtomException("Error saving media entry");
-        
+
         } catch (WebloggerException re) {
             throw new AtomException("Posting media", re);
         } catch (IOException ioe) {
             throw new AtomException("Posting media", ioe);
         }
     }
-    
-    
-    public Entry getEntry(AtomRequest areq) throws AtomException {
+
+
+    public AtomEntry getEntry(AtomRequest areq) throws AtomException {

Review Comment:
   🐞Claude Issue: **Important:** `getEntry()` (GET on a `.media-link` URI) has 
no permission check. Any authenticated user can read the media-link entry 
(name, URLs, content type) of a file in any weblog, although `getCollection()` 
in this class requires `canView` and `getMediaResource()` requires `canEdit`. 
An unknown handle also gives `website == null`, which reaches 
`getMediaFileByPath(null, ...)` and returns a 500. This was carried over from 
the Propono version, but the rewrite is the moment to make it consistent: 
return `AtomNotFoundException` when the weblog is missing and 
`AtomNotAuthorizedException` when `!RollerAtomHandler.canView(user, website)`, 
plus a test for each.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to