[ 
https://issues.apache.org/jira/browse/SLING-2156?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13072756#comment-13072756
 ] 

Antonio Sanso edited comment on SLING-2156 at 7/29/11 9:30 AM:
---------------------------------------------------------------

Highlight from the patch:

- a new property is added the to SlingPostServlet in order to enable/disable 
the error handling (false by default)
- it leverages the existing error handling as for [0]
- doesn't require any code for the end user (just adding a new jsp file under 
/sling/servlet/errorhandler)

[0] http://sling.apache.org/site/errorhandling.html

      was (Author: asanso):
    Highlight from the patch:

- a new property is added the to SlingPostServlet in order to enable/disable 
the error handling (false by default)
- it leverages the existing error handling as for [0]
- doesn't require any code for the end user (just adding a new jsp file under 
/sling/errohandloing)

[0] http://sling.apache.org/site/errorhandling.html
  
> Provide error handling for POST operations
> ------------------------------------------
>
>                 Key: SLING-2156
>                 URL: https://issues.apache.org/jira/browse/SLING-2156
>             Project: Sling
>          Issue Type: New Feature
>          Components: Servlets
>            Reporter: Antonio Sanso
>         Attachments: SLING-2156-patch.txt
>
>
> The error handling mechanism described here [0] doesn't seem to apply also to 
> POST operations.
> If an error occurs while posting a resource to repository (e.g. 
> avax.jcr.nodetype.ConstraintViolationException: no matching property 
> definition found for) the HtmlResponse.html template is rendered.
> This  can also represent a security issue since information as 
> REFERRER/technology stack are shown.
> IMHO this page should be at least configurable (if the mechanism in [0] 
> doesn't suite here).
> [0] http://sling.apache.org/site/errorhandling.html

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to