1
0
mirror of synced 2026-08-05 01:36:56 +00:00

OPEN - issue SEC-966: Consider adding escapeXml attribute to security:authentication

http://jira.springframework.org/browse/SEC-966.  Added escaping of rendered text as default.
This commit is contained in:
Luke Taylor
2008-08-26 16:21:29 +00:00
parent a4e4120443
commit d781deffe7
2 changed files with 12 additions and 7 deletions
@@ -19,6 +19,7 @@ import org.springframework.security.Authentication;
import org.springframework.security.context.SecurityContext;
import org.springframework.security.context.SecurityContextHolder;
import org.springframework.security.util.TextUtils;
import org.springframework.beans.BeanWrapperImpl;
import org.springframework.beans.BeansException;
@@ -94,7 +95,7 @@ public class AuthenticationTag extends TagSupport {
if (auth.getPrincipal() == null) {
return Tag.EVAL_PAGE;
}
try {
BeanWrapperImpl wrapper = new BeanWrapperImpl(auth);
result = wrapper.getPropertyValue(property);
@@ -120,7 +121,7 @@ public class AuthenticationTag extends TagSupport {
}
}
} else {
writeMessage(String.valueOf(result));
writeMessage(TextUtils.escapeEntities(String.valueOf(result)));
}
return EVAL_PAGE;
}