Author: olamy
Date: Thu Jun 5 14:41:39 2008
New Revision: 663748
URL: http://svn.apache.org/viewvc?rev=663748&view=rev
Log:
[CONTINUUM-1741] release.properties file containing scm credentials in plain text is visible
through the Web UI
Submitted by Napoleon Esmundo C. Ramirez
Modified:
continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java
continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java
Modified: continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java
URL: http://svn.apache.org/viewvc/continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java?rev=663748&r1=663747&r2=663748&view=diff
==============================================================================
--- continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java
(original)
+++ continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java
Thu Jun 5 14:41:39 2008
@@ -81,6 +81,11 @@
{
return REQUIRES_AUTHORIZATION;
}
+
+ if ( "release.properties".equals( currentFile ) )
+ {
+ throw new ContinuumException( "release.properties is not accessible." );
+ }
List<File> files = getContinuum().getFiles( projectId, userDirectory );
Modified: continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java
URL: http://svn.apache.org/viewvc/continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java?rev=663748&r1=663747&r2=663748&view=diff
==============================================================================
--- continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java
(original)
+++ continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java
Thu Jun 5 14:41:39 2008
@@ -96,7 +96,7 @@
String fileName = f.getName();
if ( !".cvsignore".equals( fileName ) && !"vssver.scc".equals( fileName
) &&
- !".DS_Store".equals( fileName ) )
+ !".DS_Store".equals( fileName ) && !"release.properties".equals(
fileName ) )
{
String userDirectory;
|