Hi Jacques,
I think we fixed all these ContentWrapper* code in trunk code base, but it
will affect lot of custom code as well.
So IMO we have to maintain backward compatibility as well.
Can we add an get method that will use the default encoding as html?
As we generally used ContentWrapper to
[
https://issues.apache.org/jira/browse/OFBIZ-6236?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14953403#comment-14953403
]
Jacques Le Roux commented on OFBIZ-6236:
Thanks Arun, I'm more for having this inside than ouside
[
https://issues.apache.org/jira/browse/OFBIZ-6210?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14953508#comment-14953508
]
Jacques Le Roux commented on OFBIZ-6210:
At Adrian's request continue discussion here instead than
Hi Deepak,
Thanks for the interest. I had exactly the same idea initially. There are indeed 600+
"'html" cases vs 80+ "url" ones.
But then I thought that some people will maybe not notice the difference and will always use the shorten version (the "html" one). Because it's about
security
Jacques Le Roux created OFBIZ-6668:
--
Summary: cmssite/cms/APACHE_OFBIZ_PDF does not render correcly
Key: OFBIZ-6668
URL: https://issues.apache.org/jira/browse/OFBIZ-6668
Project: OFBiz
[
https://issues.apache.org/jira/browse/OFBIZ-6669?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jacques Le Roux updated OFBIZ-6669:
---
Description:
I found a possible XSS attack through *ContentWrapper.java and ContentWorker
Hi Jacques, Deepak,
we could add the method that Deepak is proposing, for backward
compatibility, with a deprecation warning and plan for removing it before
we create our next release branch.
Jacopo
On Mon, Oct 12, 2015 at 11:50 PM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:
> Hi
[
https://issues.apache.org/jira/browse/OFBIZ-6669?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jacques Le Roux resolved OFBIZ-6669.
Resolution: Fixed
> Possible static XSS issue with Content
>
[
https://issues.apache.org/jira/browse/OFBIZ-6669?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14954165#comment-14954165
]
Jacques Le Roux commented on OFBIZ-6669:
The ContentWorker is fixed in
trunk r1708274
R14.12
[
https://issues.apache.org/jira/browse/OFBIZ-6669?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14954166#comment-14954166
]
Jacques Le Roux commented on OFBIZ-6669:
I don't close because we might want to backport those
Jacques Le Roux created OFBIZ-6669:
--
Summary: Possible static XSS issue with Content
Key: OFBIZ-6669
URL: https://issues.apache.org/jira/browse/OFBIZ-6669
Project: OFBiz
Issue Type: Bug
Damned again those unwanted changes in .classpath :/
Done by hand!
Jacques
Le 13/10/2015 02:40, jler...@apache.org a écrit :
Author: jleroux
Date: Tue Oct 13 00:40:47 2015
New Revision: 1708274
URL: http://svn.apache.org/viewvc?rev=1708274=rev
Log:
Fix for ContentWorker at OFBIZ-6669. For
It's normally complete at https://issues.apache.org/jira/browse/OFBIZ-6669
Jacques
Le 30/09/2015 23:48, Jacques Le Roux a écrit :
Actually it should be OK now, I though spotted another issue, but it seems
unrelated to this recent effort and is trivial (maybe not to fix...)
Jacques
Le
The Buildbot has detected a new failure on builder ofbiz-branch14 while
building ASF Buildbot. Full details are available at:
http://ci.apache.org/builders/ofbiz-branch14/builds/62
Buildbot URL: http://ci.apache.org/
Buildslave for this Build: lares_ubuntu
Build Reason: The
[
https://issues.apache.org/jira/browse/OFBIZ-6212?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14954435#comment-14954435
]
Deepak Dixit commented on OFBIZ-6212:
-
Hi Jacques,
I tried BIRT report and it seems issue is related
Pierre Smits created OFBIZ-6670:
---
Summary: Have configuration options for Content.
Key: OFBIZ-6670
URL: https://issues.apache.org/jira/browse/OFBIZ-6670
Project: OFBiz
Issue Type: Sub-task
[
https://issues.apache.org/jira/browse/OFBIZ-6670?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Pierre Smits reassigned OFBIZ-6670:
---
Assignee: Pierre Smits
> Have configuration options for Content.
>
17 matches
Mail list logo