Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-23934

Do not send the whole exception stack trace by default

    XMLWordPrintable

    Details

    • Tags:
    • Story Points:
      2

      Description

      When the REST API (or Automation) throws an Exception, the exception stack trace is sent:

      • if the org.nuxeo.rest.stack.enable=true parameter is present
      • if the caller set the accepted media type to application/json+nxentity

      The second one means that anybody can have the whole stack trace if the accepted media type is correctly set to application/json+nxentity.

      Make sure that the whole stack trace is only sent if the parameter org.nuxeo.rest.stack.enable is set to true.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                troger Thomas Roger
                Reporter:
                troger Thomas Roger
                Participants:
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated: