FISH-10521 Escape HTTP Characters in REST Interface #7216
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Escapes HTTP characters in the REST interface, to help lock down any XSS attempts someone may try if they have access to the application server's filesystem.
Most config which would be displayed here is protected by validation of the domain.xml, as that prevents you from having the "<" or ">" characters as values. The key files however don't have this validation, and so we must escape them.
Important Info
Blockers
None
Testing
New tests
None
Testing Performed
On a clean domain:
admin-keyfile
file under domain config:keyfile
file under domain config:ASADMIN_LISTENER_PORT
property to24848<img src=x onerror=alert(1)>
- Instances > Elated-Whalefish > PropertiesTesting Environment
Windows 11, Maven 3.9.9, Zulu JDK 11.0.26
Documentation
payara/Payara-Documentation#552
Notes for Reviewers
None