Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OF-1886: Plugin Servlet shouldn't provide access to any file on the host #1498

Conversation

guusdk
Copy link
Member

@guusdk guusdk commented Oct 3, 2019

This commit limits what files can be accessed through the plugin servlet to those that are under the Openfire home directory.

A property has been provided to disable this new restriction.

@guusdk guusdk force-pushed the OF-1886_plugin-servlet-local-file-access branch from 8fb9c8c to cf260f2 Compare November 1, 2019 14:22
@guusdk guusdk force-pushed the OF-1886_plugin-servlet-local-file-access branch from cf260f2 to 5af6e03 Compare November 1, 2019 14:30
@akrherz akrherz merged commit cb90074 into igniterealtime:master Nov 1, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants