Author: olamy Date: Thu Jun 5 14:41:39 2008 New Revision: 663748 URL: http://svn.apache.org/viewvc?rev=663748&view=rev Log: [CONTINUUM-1741] release.properties file containing scm credentials in plain text is visible through the Web UI Submitted by Napoleon Esmundo C. Ramirez Modified: continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java Modified: continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java URL: http://svn.apache.org/viewvc/continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java?rev=663748&r1=663747&r2=663748&view=diff ============================================================================== --- continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java (original) +++ continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/action/WorkingCopyAction.java Thu Jun 5 14:41:39 2008 @@ -81,6 +81,11 @@ { return REQUIRES_AUTHORIZATION; } + + if ( "release.properties".equals( currentFile ) ) + { + throw new ContinuumException( "release.properties is not accessible." ); + } List files = getContinuum().getFiles( projectId, userDirectory ); Modified: continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java URL: http://svn.apache.org/viewvc/continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java?rev=663748&r1=663747&r2=663748&view=diff ============================================================================== --- continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java (original) +++ continuum/trunk/continuum-webapp/src/main/java/org/apache/maven/continuum/web/util/WorkingCopyContentGenerator.java Thu Jun 5 14:41:39 2008 @@ -96,7 +96,7 @@ String fileName = f.getName(); if ( !".cvsignore".equals( fileName ) && !"vssver.scc".equals( fileName ) && - !".DS_Store".equals( fileName ) ) + !".DS_Store".equals( fileName ) && !"release.properties".equals( fileName ) ) { String userDirectory;