On Tue, Jan 22, 2013 at 3:26 PM, Davide <davide.sava...@gmail.com> wrote: > We're in a feature freeze state now but I need to fix those issues in > at least 2 points: SLD and WFS POST parsing. > So at the moment I'd like to just add a GeoServer setting to disable > external entities loading: it be evaluated when creating parsers for > SLD and WFS POST requests.
Hi, I've submitted two pull request to disable external entities loading in SLD and WFS POST requests parsing: https://github.com/geotools/geotools/pull/141 https://github.com/geoserver/geoserver/pull/167 In GeoServer I've added a global configuration setting to enable this feature. -- == Our support, Your Success! Visit http://opensdi.geo-solutions.it for more information. == Davide Savazzi @svzdvd Senior Software Engineer GeoSolutions S.A.S. Via Poggio alle Viti 1187 55054 Massarosa (LU) Italy phone: +39 0584 962313 fax: +39 0584 1660272 http://www.geo-solutions.it http://twitter.com/geosolutions_it ------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_mar _______________________________________________ Geoserver-devel mailing list Geoserver-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/geoserver-devel