Jacques Le Roux created OFBIZ-12851:
---------------------------------------

             Summary: Allow configuration of file name validation pattern
                 Key: OFBIZ-12851
                 URL: https://issues.apache.org/jira/browse/OFBIZ-12851
             Project: OFBiz
          Issue Type: Improvement
          Components: framework/security
    Affects Versions: Upcoming Branch
            Reporter: Jacques Le Roux
            Assignee: Jacques Le Roux
             Fix For: Upcoming Branch


Thanks to originalnichtskoenner for this PR on GH: 
[https://github.com/apache/ofbiz-framework/pull/668]. See my comment there.

<<Read file name validation pattern from security.properties to allow 
customization

Explanation: 
Hard coding the pattern made it difficult to adjust file name validation. I 
hope that making it configurable will improve this.>>

Rather than pushing the PR, which is OK with me, I'll apply as a patch locally 
and make some modifications before pushing: indentation in SecuredUpload, and 
warning about file names safeness in security.properties



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to