tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David Weinrich" <>
Subject Re: Url Encoding/Decoding and static resources
Date Thu, 28 Dec 2000 08:40:18 GMT
> ...but there might be security/implementation
> issues that I missed.

Oops! Found one big issue right after I sent off the patch. Patch now checks
for non-hex-character-strings in the encoding, and returns null if present
( similar to what happens if a control character is in the encoded string,
or if the url tries to access resources out of the context etc... ). Let's
only hope I don't find yet another error in my patch right after I send this
one out!

David Weinrich

View raw message