Liferay Issues

  • Log In Access more options
    • Online Help
    • GreenHopper Help
    • Agile Answers
    • Keyboard Shortcuts
    • About JIRA
    • JIRA Credits
    • What’s New
  • Dashboards Access more options (Alt+d)
  • Projects Access more options (Alt+p)
  • Issues Access more options (Alt+i)
  • Agile Access more options (Alt+g)
  • Test Sessions Access more options
    • Getting Started
PUBLIC - Liferay Portal Community Edition
  • PUBLIC - Liferay Portal Community Edition
  • LPS-32379 Review and Improve Security Tools
  • LPS-32821

Automated Tools - Implement concrete escaping rules

  • Agile Board
  • More Actions
  • Views
    • XML
    • Word
    • Printable

Details

  • Type: Sub-task Sub-task
  • Status: Open Open
  • Priority: Minor Minor
  • Resolution: Unresolved
  • Affects Version/s: 6.2.0 CE M4
  • Fix Version/s: None
  • Component/s: Security
  • Labels:
    None
  • Business Value:
    3
  • Similar Issues:
    Show 5 results 

    LPS-3541Suport configuring custom roles to provide access Control Panel tools
    LPS-34609PACL - Permission implementations need to follow the 0, 1, or 2 rule for Constructors
    LPS-33018PACL - Implement the rule generation API
    LPS-11526Concrete theme
    LPS-33339Implement more strict access rules when using site virtual hosts

Description

Implement concrete escaping rules so that we can improve automated tools for checking for common XSS issues.

Currently we have SourceFormatter._checkXSS() and http://www.liferay.com/community/wiki/-/wiki/Main/Escaping

Activity

  • All
  • Comments
  • Work Log
  • History
  • Activity
  • Transitions Summary
  • Commits
There are no comments yet on this issue.

People

  • Assignee:
    SE Support
    Reporter:
    Samuel Kong
    Participants of an Issue:
    Samuel Kong, SE Support
Vote (0)
Watch (0)

Dates

  • Created:
    05/Feb/13 6:18 AM
    Updated:
    05/Feb/13 6:19 AM
    Days since last comment:
    15 weeks, 1 day ago

Agile

  • View on Board
  • Atlassian JIRA (v5.2.11#854-sha1:ef00d61)
  • Report a problem
  • Powered by a free Atlassian JIRA open source license for Liferay. Try JIRA - bug tracking software for your team.