db-derby-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Bryan Pendleton <bpendleton.de...@gmail.com>
Subject Can the engine detect if it is running under an explicit SecurityManager policy?
Date Sat, 11 Jul 2015 15:28:22 GMT
I'm working on a final fix for DERBY-6807 for SqlXmlUtils, but I'd
prefer to make that change conditional, based on whether there is
a SecurityManager policy in place for the engine.

The reason for that is that if there is a SecurityManager in place,
SqlXmlUtils is already fully secure, because it delegates the
access decisions properly to the SecurityManager policy.

But if there is NOT a SecurityManager policy in effect, then it would
be more secure for SqlXmlUtils to disable certain XML features.

Is there example code that somebody can point me at which SqlXmlUtils
could use to detect whether or not a SecurityManager policy is in effect?



View raw message