Picon
Favicon

[jira] [Commented] (SLING-2320) Current DOS-prevention for infinity.json can prevent enumeration of children


    [
https://issues.apache.org/jira/browse/SLING-2320?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13197652#comment-13197652
] 

Carsten Ziegeler commented on SLING-2320:
-----------------------------------------

Is this issue solved or what needs to be done?

> Current DOS-prevention for infinity.json can prevent enumeration of children
> ----------------------------------------------------------------------------
>
>                 Key: SLING-2320
>                 URL: https://issues.apache.org/jira/browse/SLING-2320
>             Project: Sling
>          Issue Type: Bug
>          Components: Servlets
>    Affects Versions: Servlets Get 2.1.0
>            Reporter: Jeff Young
>            Assignee: Felix Meschberger
>              Labels: newbie, patch
>             Fix For: Servlets Get 2.1.4
>
>         Attachments: jsonRenderer.diff, json_get_servlet_rewrite.patch, servlet_tests.patch
>
>   Original Estimate: 1h
>  Remaining Estimate: 1h
>
> A request of resource.1.json should always succeed, as it's the primary method for JSON introspection of
(Continue reading)

Picon
Favicon

[jira] [Commented] (SLING-1725) Register internal post operations as services for consumption by servlets other than the SlingPostServlet


    [
https://issues.apache.org/jira/browse/SLING-1725?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13197654#comment-13197654
] 

Carsten Ziegeler commented on SLING-1725:
-----------------------------------------

Can we resolve this issue?

> Register internal post operations as services for consumption by servlets other than the SlingPostServlet
> ---------------------------------------------------------------------------------------------------------
>
>                 Key: SLING-1725
>                 URL: https://issues.apache.org/jira/browse/SLING-1725
>             Project: Sling
>          Issue Type: Improvement
>          Components: Servlets
>    Affects Versions: Servlets Post 2.0.4
>            Reporter: Felix Meschberger
>            Assignee: Felix Meschberger
>             Fix For: Servlets Post 2.1.2
>
>         Attachments: SLING-1725.patch
>
>
> As discussed in [1] it would be useful to have the internal operations of the Sling POST Servlet available
as services for other bundles to reuse.
> [1] http://markmail.org/message/a7vrtyhictf7tv4m

(Continue reading)

Picon
Favicon

[jira] [Commented] (SLING-1974) Accept header issues in the Sling POST Servlet


    [
https://issues.apache.org/jira/browse/SLING-1974?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13197658#comment-13197658
] 

Carsten Ziegeler commented on SLING-1974:
-----------------------------------------

I just reread this issue (in order to prepare the next release) and I fail to see how we should resolve this?
Any ideas?

> Accept header issues in the Sling POST Servlet
> ----------------------------------------------
>
>                 Key: SLING-1974
>                 URL: https://issues.apache.org/jira/browse/SLING-1974
>             Project: Sling
>          Issue Type: Bug
>          Components: Servlets
>    Affects Versions: Servlets Post 2.1.0
>            Reporter: Felix Meschberger
>             Fix For: Servlets Post 2.1.2
>
>         Attachments: SLING-1974.patch
>
>
> As of SLING-1336 the Sling POST Servlet can interpret the Accept request header to select what response
content type to render.
> Unfortunately that handling seems broken as for an Accept header like (as generated by FireFox with the
JSONovich plugin installed) :
(Continue reading)

Picon
Favicon

[jira] [Commented] (SLING-1983) Post servlet: Patching multi-value properties


    [
https://issues.apache.org/jira/browse/SLING-1983?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13197659#comment-13197659
] 

Carsten Ziegeler commented on SLING-1983:
-----------------------------------------

Can we resolve this issue?

> Post servlet: Patching multi-value properties
> ---------------------------------------------
>
>                 Key: SLING-1983
>                 URL: https://issues.apache.org/jira/browse/SLING-1983
>             Project: Sling
>          Issue Type: New Feature
>          Components: Servlets
>    Affects Versions: Servlets Post 2.1.0
>            Reporter: Alexander Klimetschek
>            Assignee: Felix Meschberger
>             Fix For: Servlets Post 2.1.2
>
>         Attachments: SLING-1983.patch
>
>
> As described on the sling list http://sling.markmail.org/thread/xxaaqowtx7jgfo3p , allow patching
of multi-value properties:
> New "@Patch" suffix:
> my:property <at> TypeHint=String[]
(Continue reading)

Picon
Favicon

[jira] [Resolved] (SLING-1725) Register internal post operations as services for consumption by servlets other than the SlingPostServlet


     [
https://issues.apache.org/jira/browse/SLING-1725?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Felix Meschberger resolved SLING-1725.
--------------------------------------

    Resolution: Fixed

Yes, resolved.

> Register internal post operations as services for consumption by servlets other than the SlingPostServlet
> ---------------------------------------------------------------------------------------------------------
>
>                 Key: SLING-1725
>                 URL: https://issues.apache.org/jira/browse/SLING-1725
>             Project: Sling
>          Issue Type: Improvement
>          Components: Servlets
>    Affects Versions: Servlets Post 2.0.4
>            Reporter: Felix Meschberger
>            Assignee: Felix Meschberger
>             Fix For: Servlets Post 2.1.2
>
>         Attachments: SLING-1725.patch
>
>
> As discussed in [1] it would be useful to have the internal operations of the Sling POST Servlet available
as services for other bundles to reuse.
> [1] http://markmail.org/message/a7vrtyhictf7tv4m
(Continue reading)

Picon
Favicon

[jira] [Commented] (SLING-1974) Accept header issues in the Sling POST Servlet


    [
https://issues.apache.org/jira/browse/SLING-1974?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13197708#comment-13197708
] 

Felix Meschberger commented on SLING-1974:
------------------------------------------

Lets postpone to the next release...

> Accept header issues in the Sling POST Servlet
> ----------------------------------------------
>
>                 Key: SLING-1974
>                 URL: https://issues.apache.org/jira/browse/SLING-1974
>             Project: Sling
>          Issue Type: Bug
>          Components: Servlets
>    Affects Versions: Servlets Post 2.1.0
>            Reporter: Felix Meschberger
>             Fix For: Servlets Post 2.1.2
>
>         Attachments: SLING-1974.patch
>
>
> As of SLING-1336 the Sling POST Servlet can interpret the Accept request header to select what response
content type to render.
> Unfortunately that handling seems broken as for an Accept header like (as generated by FireFox with the
JSONovich plugin installed) :
>    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8,application/json
(Continue reading)

Picon
Favicon

[jira] [Reopened] (SLING-1983) Post servlet: Patching multi-value properties


     [
https://issues.apache.org/jira/browse/SLING-1983?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Felix Meschberger reopened SLING-1983:
--------------------------------------

wrong resolution

> Post servlet: Patching multi-value properties
> ---------------------------------------------
>
>                 Key: SLING-1983
>                 URL: https://issues.apache.org/jira/browse/SLING-1983
>             Project: Sling
>          Issue Type: New Feature
>          Components: Servlets
>    Affects Versions: Servlets Post 2.1.0
>            Reporter: Alexander Klimetschek
>            Assignee: Felix Meschberger
>             Fix For: Servlets Post 2.1.2
>
>         Attachments: SLING-1983.patch
>
>
> As described on the sling list http://sling.markmail.org/thread/xxaaqowtx7jgfo3p , allow patching
of multi-value properties:
> New "@Patch" suffix:
> my:property <at> TypeHint=String[]
> my:property <at> Patch=true
(Continue reading)

Picon
Favicon

[jira] [Created] (SLING-2393) Update Post Servlet Documentation for patch operation

Update Post Servlet Documentation for patch operation
-----------------------------------------------------

                 Key: SLING-2393
                 URL: https://issues.apache.org/jira/browse/SLING-2393
             Project: Sling
          Issue Type: Task
          Components: Servlets
    Affects Versions: Servlets Post 2.1.0
            Reporter: Felix Meschberger

Add documentation to
http://sling.apache.org/site/manipulating-content-the-slingpostservlet-servletspost.html
with information on patch operation (see SLING-1983)

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

Picon
Favicon

[jira] [Created] (SLING-2394) Resource type might be null if provided artifact is not copied

Resource type might be null if provided artifact is not copied
--------------------------------------------------------------

                 Key: SLING-2394
                 URL: https://issues.apache.org/jira/browse/SLING-2394
             Project: Sling
          Issue Type: Bug
          Components: Installer
    Affects Versions: Installer Core 3.3.2, Installer Core 3.3.4
            Reporter: Carsten Ziegeler
            Assignee: Carsten Ziegeler
             Fix For: Installer Core 3.3.6

If the provider does not require the artifact to be copied and the provider does no resource type detection,
than the type is null which later on causes NPEs
The type should always be set

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

Picon
Favicon

[jira] [Resolved] (SLING-2394) Resource type might be null if provided artifact is not copied


     [
https://issues.apache.org/jira/browse/SLING-2394?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Carsten Ziegeler resolved SLING-2394.
-------------------------------------

    Resolution: Fixed

Fixed in revision 1239021

> Resource type might be null if provided artifact is not copied
> --------------------------------------------------------------
>
>                 Key: SLING-2394
>                 URL: https://issues.apache.org/jira/browse/SLING-2394
>             Project: Sling
>          Issue Type: Bug
>          Components: Installer
>    Affects Versions: Installer Core 3.3.2, Installer Core 3.3.4
>            Reporter: Carsten Ziegeler
>            Assignee: Carsten Ziegeler
>             Fix For: Installer Core 3.3.6
>
>
> If the provider does not require the artifact to be copied and the provider does no resource type
detection, than the type is null which later on causes NPEs
> The type should always be set

--
(Continue reading)


Gmane