/[Apache-SVN]
ViewVC logotype

Revision 1858352


Jump to revision: Previous Next
Author: mbrohl
Date: Mon Apr 29 09:24:13 2019 UTC (4 years, 11 months ago)
Changed paths: 5
Log Message:
Fixed: OWASP sanitizer breaks proper rendering of HTML code
(OFBIZ-10187)

This makes the sanitizing enabled/disabled by configuration and enhances
the functionality to support custom sanitizer policies. A reasonable 
example policy class is also included.

Thanks Dennis Balkir for reporting and providing the patch.

Changed paths

Path Details
Directoryofbiz/ofbiz-framework/trunk/framework/base/config/owasp.properties modified , text changed
Directoryofbiz/ofbiz-framework/trunk/framework/base/src/main/java/org/apache/ofbiz/base/html/ added
Directoryofbiz/ofbiz-framework/trunk/framework/base/src/main/java/org/apache/ofbiz/base/html/CustomPermissivePolicy.java added
Directoryofbiz/ofbiz-framework/trunk/framework/base/src/main/java/org/apache/ofbiz/base/html/SanitizerCustomPolicy.java added
Directoryofbiz/ofbiz-framework/trunk/framework/base/src/main/java/org/apache/ofbiz/base/util/UtilCodec.java modified , text changed

infrastructure at apache.org
ViewVC Help
Powered by ViewVC 1.1.26