From commits-return-6546-apmail-continuum-commits-archive=continuum.apache.org@continuum.apache.org Tue Aug 7 13:23:15 2012 Return-Path: X-Original-To: apmail-continuum-commits-archive@www.apache.org Delivered-To: apmail-continuum-commits-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id A430CC040 for ; Tue, 7 Aug 2012 13:23:15 +0000 (UTC) Received: (qmail 88932 invoked by uid 500); 7 Aug 2012 13:23:15 -0000 Delivered-To: apmail-continuum-commits-archive@continuum.apache.org Received: (qmail 88877 invoked by uid 500); 7 Aug 2012 13:23:15 -0000 Mailing-List: contact commits-help@continuum.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@continuum.apache.org Delivered-To: mailing list commits@continuum.apache.org Received: (qmail 88867 invoked by uid 99); 7 Aug 2012 13:23:14 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 07 Aug 2012 13:23:14 +0000 X-ASF-Spam-Status: No, hits=-2000.0 required=5.0 tests=ALL_TRUSTED X-Spam-Check-By: apache.org Received: from [140.211.11.4] (HELO eris.apache.org) (140.211.11.4) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 07 Aug 2012 13:23:12 +0000 Received: from eris.apache.org (localhost [127.0.0.1]) by eris.apache.org (Postfix) with ESMTP id AEE0F23888E3 for ; Tue, 7 Aug 2012 13:22:14 +0000 (UTC) Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: svn commit: r1370246 - /continuum/trunk/continuum-webapp/src/main/resources/struts.xml Date: Tue, 07 Aug 2012 13:22:14 -0000 To: commits@continuum.apache.org From: brett@apache.org X-Mailer: svnmailer-1.0.8-patched Message-Id: <20120807132214.AEE0F23888E3@eris.apache.org> X-Virus-Checked: Checked by ClamAV on apache.org Author: brett Date: Tue Aug 7 13:22:14 2012 New Revision: 1370246 URL: http://svn.apache.org/viewvc?rev=1370246&view=rev Log: [CONTINUUM-2684] defaultStack requires a stronger blacklist of parameter names in the param interceptor Modified: continuum/trunk/continuum-webapp/src/main/resources/struts.xml Modified: continuum/trunk/continuum-webapp/src/main/resources/struts.xml URL: http://svn.apache.org/viewvc/continuum/trunk/continuum-webapp/src/main/resources/struts.xml?rev=1370246&r1=1370245&r2=1370246&view=diff ============================================================================== --- continuum/trunk/continuum-webapp/src/main/resources/struts.xml (original) +++ continuum/trunk/continuum-webapp/src/main/resources/struts.xml Tue Aug 7 13:22:14 2012 @@ -18,27 +18,66 @@ --> + "http://struts.apache.org/dtds/struts-2.0.dtd"> - + - + + + + + + + + + + + + + + + + + dojo\..*,^struts\..*,.*\\.*,.*\(.*,.*\).*,.*@.* + + + + input,back,cancel,browse + + + input,back,cancel,browse + + + + + + + + + + + + dojo\..*,^struts\..*,.*\\.*,.*\(.*,.*\).*,.*@.* + + + + - + @@ -76,7 +115,7 @@ input,back,cancel,browse,edit - + @@ -89,7 +128,7 @@ RETRIEVE - + @@ -186,14 +225,14 @@ /WEB-INF/jsp/components/companyLogo.jsp - + - + /WEB-INF/jsp/navigations/DefaultBottom.jsp - - - + + + @@ -202,16 +241,16 @@ /WEB-INF/jsp/addMavenTwoProject.jsp - - + + 200 50 - - /WEB-INF/jsp/navigations/wait.jsp + + /WEB-INF/jsp/navigations/wait.jsp /WEB-INF/jsp/addMavenTwoProject.jsp groupSummary @@ -222,12 +261,12 @@ /WEB-INF/jsp/addMavenOneProject.jsp - - + + - /WEB-INF/jsp/navigations/wait.jsp + /WEB-INF/jsp/navigations/wait.jsp /WEB-INF/jsp/addMavenOneProject.jsp groupSummary @@ -380,7 +419,7 @@ groupSummary - + @@ -417,7 +456,7 @@ /WEB-INF/jsp/buildResults.jsp - + @@ -435,14 +474,14 @@ ${projectGroupId} - + buildOutputInputStream attachment; filename="build-output.txt" - - + + remove @@ -466,7 +505,7 @@ ${fileLength} - + application/octet-stream @@ -478,7 +517,7 @@ /WEB-INF/jsp/scmResult.jsp - + @@ -495,7 +534,7 @@ schedules schedule - + /WEB-INF/jsp/confirmScheduleRemoval.jsp schedules @@ -508,13 +547,13 @@ buildResults - + projectGroupSummary ${projectGroupId} - + @@ -656,7 +695,7 @@ /WEB-INF/jsp/releases.jsp - + /WEB-INF/jsp/viewProjectBuildsReport.jsp @@ -665,7 +704,7 @@ /WEB-INF/jsp/viewProjectBuildsReport.jsp /WEB-INF/jsp/viewProjectBuildsReport.jsp - + /WEB-INF/jsp/viewProjectBuildsReport.jsp /WEB-INF/jsp/viewProjectBuildsReport.jsp @@ -696,15 +735,15 @@ /WEB-INF/jsp/admin/appearance.jsp - + /WEB-INF/jsp/admin/appearance.jsp /WEB-INF/jsp/admin/appearance.jsp saveFooter - - + + /WEB-INF/jsp/admin/editAppearance.jsp @@ -731,25 +770,25 @@ execute - + - + --> + /WEB-INF/jsp/admin/profilesList.jsp - - + + - /WEB-INF/jsp/admin/editProfile.jsp + /WEB-INF/jsp/admin/editProfile.jsp - + /WEB-INF/jsp/admin/editProfile.jsp /WEB-INF/jsp/admin/editProfile.jsp - + delete @@ -759,67 +798,67 @@ /admin list - - + + /WEB-INF/jsp/admin/confirmDeleteBuildEnv.jsp - - + + /WEB-INF/jsp/admin/profilesList.jsp /WEB-INF/jsp/admin/editProfile.jsp /WEB-INF/jsp/admin/editProfile.jsp - + /WEB-INF/jsp/admin/editProfile.jsp - /WEB-INF/jsp/admin/editProfile.jsp - - + /WEB-INF/jsp/admin/editProfile.jsp + + /WEB-INF/jsp/admin/editProfile.jsp /WEB-INF/jsp/admin/editProfile.jsp - + + --> /WEB-INF/jsp/admin/installationsTypeChoice.jsp - + /WEB-INF/jsp/admin/installationsList.jsp - - + + /WEB-INF/jsp/admin/editInstallation.jsp - /WEB-INF/jsp/admin/editInstallation.jsp + /WEB-INF/jsp/admin/editInstallation.jsp - + /WEB-INF/jsp/admin/editInstallation.jsp installationsList - - + + /WEB-INF/jsp/admin/installationsList.jsp /WEB-INF/jsp/admin/installationsList.jsp /WEB-INF/jsp/admin/confirmDeleteInstallation.jsp - - + + + --> /WEB-INF/jsp/admin/buildDefinitionTemplateSummary.jsp - + /WEB-INF/jsp/admin/editBuildDefinitionTemplate.jsp /WEB-INF/jsp/admin/editBuildDefinitionTemplate.jsp - + /WEB-INF/jsp/admin/editBuildDefinitionTemplate.jsp /WEB-INF/jsp/admin/editBuildDefinitionTemplate.jsp @@ -827,26 +866,26 @@ - buildDefinitionTemplates.action + buildDefinitionTemplates.action /WEB-INF/jsp/admin/confirmDeleteBuildDefinitionTemplate.jsp delete - + buildDefinitionTemplates.action /WEB-INF/jsp/admin/editBuildDefinitionTemplate.jsp - + /WEB-INF/jsp/admin/editBuildDefinitionAsTemplate.jsp /WEB-INF/jsp/admin/editBuildDefinitionAsTemplate.jsp - + buildDefinitionTemplates.action @@ -860,54 +899,54 @@ /WEB-INF/jsp/admin/editBuildDefinitionAsTemplate.jsp - + buildDefinitionTemplates.action /WEB-INF/jsp/admin/confirmDeleteBuildDefinitionAsTemplate.jsp - + /WEB-INF/jsp/admin/buildQueueView.jsp /WEB-INF/jsp/admin/viewDistributedBuilds.jsp - + displayQueues - - - + + + displayQueues - - - + + + displayQueues - - - + + + displayQueues - + - + displayQueues - - - + + + displayQueues - - + + @@ -920,7 +959,7 @@ displayQueues - + displayQueues @@ -950,26 +989,27 @@ displayQueues - + - + /WEB-INF/jsp/admin/parallelbuilds.jsp - + - /WEB-INF/jsp/admin/editParallelBuilds.jsp + /WEB-INF/jsp/admin/editParallelBuilds.jsp - + /WEB-INF/jsp/admin/editParallelBuilds.jsp /WEB-INF/jsp/admin/editParallelBuilds.jsp buildQueueList - - - + + + /WEB-INF/jsp/admin/confirmDeleteBuildQueue.jsp buildQueueList @@ -978,21 +1018,21 @@ delete - + - + /WEB-INF/jsp/admin/localRepositoriesList.jsp - + /WEB-INF/jsp/admin/editLocalRepository.jsp /WEB-INF/jsp/admin/editLocalRepository.jsp - + /WEB-INF/jsp/admin/editLocalRepository.jsp /WEB-INF/jsp/admin/editLocalRepository.jsp @@ -1000,7 +1040,7 @@ repositoryList - + remove @@ -1010,41 +1050,41 @@ repositoryList - + repositoryList - + - /WEB-INF/jsp/admin/purgeConfigurationsList.jsp - /WEB-INF/jsp/admin/distributedPurgeConfigurationsList.jsp + /WEB-INF/jsp/admin/purgeConfigurationsList.jsp + /WEB-INF/jsp/admin/distributedPurgeConfigurationsList.jsp - + /WEB-INF/jsp/admin/purgeConfigurationsList.jsp - + /WEB-INF/jsp/admin/editPurgeConfiguration.jsp /WEB-INF/jsp/admin/editPurgeConfiguration.jsp - + /WEB-INF/jsp/admin/editPurgeConfiguration.jsp displayPurge - + purgeConfigList @@ -1058,7 +1098,7 @@ remove - + displayPurge @@ -1076,14 +1116,14 @@ /WEB-INF/jsp/admin/editDistributedPurgeConfiguration.jsp /WEB-INF/jsp/admin/editDistributedPurgeConfiguration.jsp - + /WEB-INF/jsp/admin/editDistributedPurgeConfiguration.jsp displayPurge - + purgeConfigList @@ -1097,7 +1137,7 @@ remove - + displayPurge @@ -1111,16 +1151,16 @@ - + /WEB-INF/jsp/admin/buildAgentsList.jsp - + /WEB-INF/jsp/admin/editBuildAgent.jsp /WEB-INF/jsp/admin/editBuildAgent.jsp - + /WEB-INF/jsp/admin/editBuildAgent.jsp /WEB-INF/jsp/admin/editBuildAgent.jsp @@ -1128,7 +1168,7 @@ buildAgentList - + buildAgentList @@ -1142,7 +1182,7 @@ delete - + /WEB-INF/jsp/admin/viewBuildAgent.jsp @@ -1367,6 +1407,6 @@ /WEB-INF/jsp/notifier/notifierWagon.jsp projectGroupNotifier - +