[jira] [Commented] (VELTOOLS-126) XSS Vulnerability when using struts/ErrorsTool.getMsgs

2012-03-07 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELTOOLS-126?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13224527#comment-13224527 ] Christopher Schultz commented on VELTOOLS-126: -- Here's a stab at a patch. I

[jira] [Commented] (VELTOOLS-126) XSS Vulnerability when using struts/ErrorsTool.getMsgs

2012-03-07 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELTOOLS-126?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13224501#comment-13224501 ] Christopher Schultz commented on VELTOOLS-126: -- ErrorsTool now uses StrutsU

[jira] [Commented] (VELTOOLS-152) ValidatorTool generates invalid XHTML even when in XHTML mode

2012-03-06 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELTOOLS-152?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13223732#comment-13223732 ] Christopher Schultz commented on VELTOOLS-152: -- Fixed in trunk: r1297753 Fi

[jira] [Commented] (VELTOOLS-136) SortTool fails on null values

2012-01-31 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELTOOLS-136?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13197024#comment-13197024 ] Christopher Schultz commented on VELTOOLS-136: -- Did you mean that SortTool

[jira] [Commented] (VELTOOLS-150) VelocityLayoutServlet allows clients to specify "layout" without performing any security checks.

2012-01-20 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELTOOLS-150?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13189838#comment-13189838 ] Christopher Schultz commented on VELTOOLS-150: -- Sure, I can do a simple fix

[jira] [Commented] (VELOCITY-731) Velocity 1.6 performance is degraded by introduced toString() calls

2012-01-17 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELOCITY-731?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13187966#comment-13187966 ] Christopher Schultz commented on VELOCITY-731: -- Colin, So your bean has a

[jira] [Commented] (VELTOOLS-150) VelocityLayoutServlet allows clients to specify "layout" without performing any security checks.

2012-01-09 Thread Christopher Schultz (Commented) (JIRA)
[ https://issues.apache.org/jira/browse/VELTOOLS-150?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13182702#comment-13182702 ] Christopher Schultz commented on VELTOOLS-150: -- I see us having several opt