Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-21695

Upgrade FreeMarker and use escaping by default

    XMLWordPrintable

    Details

      Description

      Since FreeMarker 2.3.24 it's possible to associate an output format to FreeMarker templates, either by code or by using specific extensions.

      We should take advantage of that and escape everything by default, to avoid undiagnosed XSS issues.

      References:
      http://freemarker.org/docs/dgui_misc_autoescaping.html
      http://freemarker.org/docs/pgui_config_outputformatsautoesc.html
      http://stackoverflow.com/questions/1265488/default-escaping-in-freemarker#36294233

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated: