Re: XSS in Web interface

2011-04-06 Thread Dejan Bosanac
Hi Javier, ActiveMQ admin console (/admin) has been protected from XSS (see https://issues.apache.org/jira/browse/AMQ-2625 for more info). I guess camel web console needs some work in that area (all contributions are welcomed). The thing is that broker installations are usually not publicly deplo

XSS in Web interface

2011-04-05 Thread Javier Godinez
ActiveMQ Developers, A quick question regarding cross-site script vulnerabilities in the web interface. Is the Web interface intended to be accessible during production, or is that simply used during development? If it is intended to be used in production, is there a reason for the lack of input f