hadoop-hdfs-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Hadoop QA (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HDFS-4162) Some malformed and unquoted HTML strings are returned from datanode web ui
Date Thu, 08 Nov 2012 21:46:13 GMT

    [ https://issues.apache.org/jira/browse/HDFS-4162?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13493524#comment-13493524

Hadoop QA commented on HDFS-4162:

{color:green}+1 overall{color}.  Here are the results of testing the latest attachment 
  against trunk revision .

    {color:green}+1 @author{color}.  The patch does not contain any @author tags.

    {color:green}+1 tests included{color}.  The patch appears to include 1 new or modified
test files.

    {color:green}+1 javac{color}.  The applied patch does not increase the total number of
javac compiler warnings.

    {color:green}+1 javadoc{color}.  The javadoc tool did not generate any warning messages.

    {color:green}+1 eclipse:eclipse{color}.  The patch built with eclipse:eclipse.

    {color:green}+1 findbugs{color}.  The patch does not introduce any new Findbugs (version
1.3.9) warnings.

    {color:green}+1 release audit{color}.  The applied patch does not increase the total number
of release audit warnings.

    {color:green}+1 core tests{color}.  The patch passed unit tests in hadoop-hdfs-project/hadoop-hdfs.

    {color:green}+1 contrib tests{color}.  The patch passed contrib unit tests.

Test results: https://builds.apache.org/job/PreCommit-HDFS-Build/3466//testReport/
Console output: https://builds.apache.org/job/PreCommit-HDFS-Build/3466//console

This message is automatically generated.
> Some malformed and unquoted HTML strings are returned from datanode web ui
> --------------------------------------------------------------------------
>                 Key: HDFS-4162
>                 URL: https://issues.apache.org/jira/browse/HDFS-4162
>             Project: Hadoop HDFS
>          Issue Type: Bug
>          Components: data-node
>    Affects Versions: 0.23.4
>            Reporter: Derek Dagit
>            Assignee: Derek Dagit
>            Priority: Minor
>         Attachments: HDFS-4162-branch-0.23.patch, HDFS-4162.patch
> When browsing to the datanode at /browseDirectory.jsp, if a path with HTML characters
is requested, the resulting error page echos back the input unquoted.
> Example:
> http://localhost:50075/browseDirectory.jsp?dir=/<xss>&go=go&namenodeInfoPort=50070&nnaddr=localhost%3A9000
> Writes an input element as part of the response:
> <input name="dir" type="text" width="50" id"dir" value="/<xss>">
> - The value of the "value" attribute is not quoted. 
> - An = must follow the "id" attribute name.
> - Element "input" should have a closing tag.
> The output should be something like:
> <input name="dir" type="text" width="50" id="dir" value="/&lt;xss&gt;"/>
> In addition, if one creates a directory:
> hdfs dfs -put '/some/path/to/<xss>'
> Then browsing to the parent of directory '<xss>' prints unquoted HTML in the directory

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

View raw message