Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [aspectj-users] Plans for dflow pointcut

Thanks Andy, I've submitted Bug 243793 as an enhancement.

On one hand I'd like to volunteer to help in the implementation of
this feature, on the other hand I don't really have experience in
compiler-level code so I think I might actually hamper efforts. If you
can think of any way that I can help, please let me know.



On Mon, Aug 11, 2008 at 11:40 AM, Andy Clement <andrew.clement@xxxxxxxxx> wrote:
> Hi Rohit,
> I would say we haven't had time to even look at whether we'd want to do
> that, so it hasn't already been dismissed.  There is no bugzilla entry for
> it, and if it isn't in bugzilla then it is completely off the radar.  Feel
> free to raise a bugzilla entry so it is at least being tracked and it will
> get reviewed at some point.
> cheers,
> Andy.
> 2008/8/11 Rohit Lists <rklists@xxxxxxxxx>
>> Hello, are there are any plans to implement the data flow pointcut as
>> defined here
>> in AspectJ? This would be an invaluable resource to application
>> security since large classes of security problems deal with tracing
>> data from source to sink (e.g. cross site scripting,
>> SQL/XML/Xpath/Ldap injection, OS interaction vulnerabilities, etc.).
>> If there are no such plans, is it because there are not enough
>> resources to work on this? Has there already been a discussion on
>> implementing dflow pointcut and a decision was made not to implement
>> it?
>> Thanks,
>> --
>> Rohit Sethi
>> Security Compass
>> _______________________________________________
>> aspectj-users mailing list
>> aspectj-users@xxxxxxxxxxx
> _______________________________________________
> aspectj-users mailing list
> aspectj-users@xxxxxxxxxxx

Rohit Sethi
Security Compass

Back to the top