incubator-jspwiki-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Janne Jalkanen <Janne.Jalka...@ecyrd.com>
Subject Re: Security question on SET
Date Mon, 27 Oct 2008 21:22:31 GMT
> Has anyone does this already? Or is there an understanding that there
> are no security issues here? (I'm thinking of things like permitting
> HTML parsing for a single page, etc.  -- there might be others more
> subtle.)

In short: yes.  Only a subset of properties, deemed safe, are allowed  
to override the jspwiki.properties.  These aren't unfortunately  
really documented anywhere. :-/

/Janne

Mime
View raw message