Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LPS-134338 JavaScript is executed when store XSS in page name during page creation #4942

Closed
wants to merge 1 commit into from

Conversation

lfbesada
Copy link
Collaborator

No description provided.

@lfbesada lfbesada added the 🔍 Backend Review Needed Backend code needs to be reviewed by a member of the team. label Jun 21, 2021
@liferay-continuous-integration
Copy link
Collaborator

To conserve resources, the PR Tester does not automatically run for every pull.

If your code changes were already tested in another pull, reference that pull in this pull so the test results can be analyzed.

If your pull was never tested, comment "ci:test" to run the PR Tester for this pull.

@lfbesada
Copy link
Collaborator Author

ci:test:sf

@lfbesada
Copy link
Collaborator Author

ci:test:relevant

@liferay-continuous-integration
Copy link
Collaborator

✔️ ci:test:sf - 1 out of 1 jobs passed in 3 minutes

Click here for more details.

Base Branch:

Branch Name: master
Branch GIT ID: 8f7e53cd039dbbc0fa2fc5afffce1de7fbdbd9ac

Sender Branch:

Branch Name: LPS-134338
Branch GIT ID: e48769173c30b7af7c0efa6eb1aea379ba3becb5

1 out of 1jobs PASSED
1 Successful Jobs:
For more details click here.

@ealonso ealonso added ✅ Ready to Merge Pull request is ready and can be forwarded. and removed 🔍 Backend Review Needed Backend code needs to be reviewed by a member of the team. labels Jun 21, 2021
@liferay-continuous-integration
Copy link
Collaborator

@liferay-continuous-integration
Copy link
Collaborator

❌ ci:test:stable - 9 out of 10 jobs passed

❌ ci:test:relevant - 21 out of 25 jobs passed in 3 hours 47 minutes

Click here for more details.

Base Branch:

Branch Name: master
Branch GIT ID: 8f7e53cd039dbbc0fa2fc5afffce1de7fbdbd9ac

Upstream Comparison:

Branch GIT ID: 8f7e53cd039dbbc0fa2fc5afffce1de7fbdbd9ac
Jenkins Build URL: Acceptance Upstream DXP (master) #2019

ci:test:stable - 9 out of 10 jobs PASSED
9 Successful Jobs:
ci:test:relevant - 21 out of 25 jobs PASSED
21 Successful Jobs:
For more details click here.

Failures unique to this pull:

  1. test-portal-acceptance-pullrequest-batch(master)/js-unit-jdk8/0
    Job Results:

    0 Tests Passed.
    1 Test Failed.

    1. AXIS_VARIABLE=0,label_exp=!master #499940
           [exec] * What went wrong:
           [exec] Execution failed for task ':apps:frontend-js:frontend-js-a11y-web:packageRunTest'.
           [exec] > Process 'command '/opt/dev/projects/github/liferay-portal/build/node/bin/node'' finished with non-zero exit value 1
           [exec] 
           [exec] * Try:
           [exec] Run with --info or --debug option to get more log output. Run with --scan to get full insights.
           [exec] 
           [exec] * Exception is:
           [exec] org.gradle.api.tasks.TaskExecutionException: Execution failed for task ':apps:frontend-js:frontend-js-a11y-web:packageRunTest'.
           [exec] 	at org.gradle.api.internal.tasks.execution.ExecuteActionsTaskExecuter.lambda$executeIfValid$1(ExecuteActionsTaskExecuter.java:208)
           [exec] 	at org.gradle.internal.Try$Failure.ifSuccessfulOrElse(Try.java:263)
           [exec] 	at org.gradle.api.internal.tasks.execution.ExecuteActionsTaskExecuter.executeIfValid(ExecuteActionsTaskExecuter.java:206)
           [exec] 	at org.gradle.api.internal.tasks.execution.ExecuteActionsTaskExecuter.execute(ExecuteActionsTaskExecuter.java:187)
           [exec] 	at org.gradle.api.internal.tasks.execution.CleanupStaleOutputsExecuter.execute(CleanupStaleOutputsExecuter.java:114)
           [exec] 	at org.gradle.api.internal.tasks.execution.FinalizePropertiesTaskExecuter.execute(FinalizePropertiesTaskExecuter.java:46)
           [exec] 	at org.gradle.api.internal.tasks.execution.ResolveTaskExecutionModeExecuter.execute(ResolveTaskExecutionModeExecuter.java:62)
           [exec] 	at org.gradle.api.internal.tasks.execution.SkipTaskWithNoActionsExecuter.execute(SkipTaskWithNoActionsExecuter.java:57)
           [exec] 	at org.gradle.api.internal.tasks.execution.SkipOnlyIfTaskExecuter.execute(SkipOnlyIfTaskExecuter.java:56)
           [exec] 	at org.gradle.api.internal.tasks.execution.CatchExceptionTaskExecuter.execute(CatchExceptionTaskExecuter.java:36)
           [exec] 	at org.gradle.api.internal.tasks.execution.EventFiringTaskExecuter$1.executeTask(EventFiringTaskExecuter.java:77)
           [exec] 	at org.gradle.api.internal.tasks.execution.EventFiringTaskExecuter$1.call(EventFiringTaskExecuter.java:55)
           [exec] 	at org.gradle.api.internal.tasks.execution.EventFiringTaskExecuter$1.call(EventFiringTaskExecuter.java:52)
           [exec] 	at org.gradle.internal.operations.DefaultBuildOperationExecutor$CallableBuildOperationWorker.execute(DefaultBuildOperationExecutor.java:409)

Failures in common with acceptance upstream results at 8f7e53c:
  1. test-portal-acceptance-pullrequest-batch(master)/modules-integration-mysql57-jdk8/0
    Job Results:

    1179 Tests Passed.
    31 Tests Failed.

    1. AXIS_VARIABLE=2,label_exp=!master #12359
      1. com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomCanonicalURL
        java.lang.NullPointerException
        	at com.liferay.questions.web.internal.layout.seo.QuestionsLayoutSEOLinkManagerImpl.getLocalizedLayoutSEOLinks(QuestionsLayoutSEOLinkManagerImpl.java:80)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.OpenGraphTopHeadDynamicInclude.include(OpenGraphTopHeadDynamicInclude.java:117)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.lambda$testIncludeCustomCanonicalURL$0(OpenGraphTopHeadDynamicIncludeTest.java:161)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest._testWithLayoutSEOCompanyConfiguration(OpenGraphTopHeadDynamicIncludeTest.java:1252)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomCanonicalURL(OpenGraphTopHeadDynamicIncludeTest.java:160)
        	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        	at java.lang.reflect.Method.invoke(Method.java:498)
        	at com.liferay.arquillian.extension.junit.bridge.server.TestExecutorRunnable$3.evaluate(TestExecutorRunnable.java:353)
        	at org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.eval...
      2. com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomDescription
        java.lang.NullPointerException
        	at com.liferay.questions.web.internal.layout.seo.QuestionsLayoutSEOLinkManagerImpl.getLocalizedLayoutSEOLinks(QuestionsLayoutSEOLinkManagerImpl.java:80)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.OpenGraphTopHeadDynamicInclude.include(OpenGraphTopHeadDynamicInclude.java:117)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.lambda$testIncludeCustomDescription$1(OpenGraphTopHeadDynamicIncludeTest.java:192)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest._testWithLayoutSEOCompanyConfiguration(OpenGraphTopHeadDynamicIncludeTest.java:1252)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomDescription(OpenGraphTopHeadDynamicIncludeTest.java:191)
        	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        	at java.lang.reflect.Method.invoke(Method.java:498)
        	at com.liferay.arquillian.extension.junit.bridge.server.TestExecutorRunnable$3.evaluate(TestExecutorRunnable.java:353)
        	at org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evalua...
      3. com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomMetaTags
        java.lang.NullPointerException
        	at com.liferay.questions.web.internal.layout.seo.QuestionsLayoutSEOLinkManagerImpl.getLocalizedLayoutSEOLinks(QuestionsLayoutSEOLinkManagerImpl.java:80)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.OpenGraphTopHeadDynamicInclude.include(OpenGraphTopHeadDynamicInclude.java:117)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomMetaTags(OpenGraphTopHeadDynamicIncludeTest.java:232)
        	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        	at java.lang.reflect.Method.invoke(Method.java:498)
        	at com.liferay.arquillian.extension.junit.bridge.server.TestExecutorRunnable$3.evaluate(TestExecutorRunnable.java:353)
        	at org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTe...
      4. ...
    2. AXIS_VARIABLE=3,label_exp=!master #12359
      1. com.liferay.layout.set.prototype.exportimport.test.LayoutSetPrototypeExportImportTest.classMethod
        org.springframework.orm.hibernate3.HibernateOptimisticLockingFailureException: Object of class [com.liferay.portal.model.impl.LayoutSetPrototypeImpl] with identifier [42080]: optimistic locking failed; nested exception is org.hibernate.StaleObjectStateException: Row was updated or deleted by another transaction (or unsaved-value mapping was incorrect): [com.liferay.portal.model.impl.LayoutSetPrototypeImpl#42080]
        	at org.springframework.orm.hibernate3.SessionFactoryUtils.convertHibernateAccessException(SessionFactoryUtils.java:699)
        	at org.springframework.orm.hibernate3.SpringSessionSynchronization.translateException(SpringSessionSynchronization.java:165)
        	at org.springframework.orm.hibernate3.SpringSessionSynchronization.beforeCommit(SpringSessionSynchronization.java:153)
        	at org.springframework.transaction.support.TransactionSynchronizationUtils.triggerBeforeCommit(TransactionSynchronizationUtils.java:96)
        	at org.springframework.transaction.support.AbstractPlatformTransactionManager.triggerBeforeCommit(AbstractPlatformTransactionManager.java:919)
        	at org.springframework.transaction.support.AbstractPlatformTransactionManager.processCommit(AbstractPlatformTransactionManager.java:727)
        	at org.springframework.transaction.support.AbstractPlatformTransactionManager.commit(AbstractPlatformTransactionManager.java:711)
        	at com.liferay.portal.spring.transaction.DefaultTransactionExecutor.commit(DefaultTransactionExecutor.java:41)
        	at com.liferay.portal.spring.transaction.BaseTransa...

@liferay-continuous-integration
Copy link
Collaborator

@lfbesada
Copy link
Collaborator Author

ci:test:relevant

@liferay-continuous-integration
Copy link
Collaborator

✔️ ci:test:stable - 10 out of 10 jobs passed

✔️ ci:test:relevant - 23 out of 25 jobs passed in 4 hours 16 minutes

Click here for more details.

Base Branch:

Branch Name: master
Branch GIT ID: 7e3274c81108ee9a3292f7479552ac9f42faad0b

Upstream Comparison:

Branch GIT ID: 7e3274c81108ee9a3292f7479552ac9f42faad0b
Jenkins Build URL: Acceptance Upstream DXP (master) #2021

ci:test:stable - 10 out of 10 jobs PASSED
10 Successful Jobs:
ci:test:relevant - 22 out of 25 jobs PASSED
22 Successful Jobs:
For more details click here.

Failures unique to this pull:


Failures in common with acceptance upstream results at 7e3274c:
  1. test-portal-acceptance-pullrequest-batch(master)/modules-integration-mysql57-jdk8/0
    Job Results:

    1175 Tests Passed.
    31 Tests Failed.

    1. AXIS_VARIABLE=2,label_exp=!master #416963
      1. com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomCanonicalURL
        java.lang.NullPointerException
        	at com.liferay.questions.web.internal.layout.seo.QuestionsLayoutSEOLinkManagerImpl.getLocalizedLayoutSEOLinks(QuestionsLayoutSEOLinkManagerImpl.java:80)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.OpenGraphTopHeadDynamicInclude.include(OpenGraphTopHeadDynamicInclude.java:117)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.lambda$testIncludeCustomCanonicalURL$0(OpenGraphTopHeadDynamicIncludeTest.java:161)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest._testWithLayoutSEOCompanyConfiguration(OpenGraphTopHeadDynamicIncludeTest.java:1252)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomCanonicalURL(OpenGraphTopHeadDynamicIncludeTest.java:160)
        	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        	at java.lang.reflect.Method.invoke(Method.java:498)
        	at com.liferay.arquillian.extension.junit.bridge.server.TestExecutorRunnable$3.evaluate(TestExecutorRunnable.java:353)
        	at org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.eval...
      2. com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomDescription
        java.lang.NullPointerException
        	at com.liferay.questions.web.internal.layout.seo.QuestionsLayoutSEOLinkManagerImpl.getLocalizedLayoutSEOLinks(QuestionsLayoutSEOLinkManagerImpl.java:80)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.OpenGraphTopHeadDynamicInclude.include(OpenGraphTopHeadDynamicInclude.java:117)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.lambda$testIncludeCustomDescription$1(OpenGraphTopHeadDynamicIncludeTest.java:192)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest._testWithLayoutSEOCompanyConfiguration(OpenGraphTopHeadDynamicIncludeTest.java:1252)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomDescription(OpenGraphTopHeadDynamicIncludeTest.java:191)
        	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        	at java.lang.reflect.Method.invoke(Method.java:498)
        	at com.liferay.arquillian.extension.junit.bridge.server.TestExecutorRunnable$3.evaluate(TestExecutorRunnable.java:353)
        	at org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evalua...
      3. com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomMetaTags
        java.lang.NullPointerException
        	at com.liferay.questions.web.internal.layout.seo.QuestionsLayoutSEOLinkManagerImpl.getLocalizedLayoutSEOLinks(QuestionsLayoutSEOLinkManagerImpl.java:80)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.OpenGraphTopHeadDynamicInclude.include(OpenGraphTopHeadDynamicInclude.java:117)
        	at com.liferay.layout.seo.web.internal.servlet.taglib.test.OpenGraphTopHeadDynamicIncludeTest.testIncludeCustomMetaTags(OpenGraphTopHeadDynamicIncludeTest.java:232)
        	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        	at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        	at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        	at java.lang.reflect.Method.invoke(Method.java:498)
        	at com.liferay.arquillian.extension.junit.bridge.server.TestExecutorRunnable$3.evaluate(TestExecutorRunnable.java:353)
        	at org.junit.internal.runners.statements.RunBefores.evaluate(RunBefores.java:26)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTestRule$2.evaluate(AbstractTestRule.java:99)
        	at com.liferay.portal.kernel.test.rule.AbstractTe...
      4. ...

@liferay-continuous-integration
Copy link
Collaborator

@Tim-Cao
Copy link

Tim-Cao commented Jun 21, 2021

ci:forward

@liferay-continuous-integration
Copy link
Collaborator

CI is automatically triggering the following test suites:

  •     ci:test:relevant
  •     ci:test:sf

The pull request will automatically be forwarded to the user brianchandotcom if the following test suites pass:

  •     ci:test:relevant
  •     ci:test:sf
  •     ci:test:stable

@liferay-continuous-integration
Copy link
Collaborator

Skipping previously passed test suites:
ci:test:relevant
ci:test:sf

@liferay-continuous-integration
Copy link
Collaborator

All required test suite(s) passed.
Forwarding pull request to brianchandotcom.
Console

@liferay-continuous-integration
Copy link
Collaborator

Pull request has been successfully forwarded to brianchandotcom#103457
Console

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
4 participants