[
Date Prev][
Date Next][
Thread Prev][
Thread Next][
Date Index][
Thread Index]
[
List Home]
Re: [jetty-users] Examples for SymlinkAllowedResourceAliasChecker in XML config file
|
- From: Fab Stz <fabstz-it@xxxxxxxx>
- Date: Thu, 26 Jun 2025 09:21:26 +0200
- Autocrypt: addr=fabstz-it@xxxxxxxx; keydata= mQINBFlSgXwBEADLyaDJAMj3rJ25Pt2zHKPhekNBrSSD1bU9jyob1eYyvIfhrDvBfS+5WfPLhcmi bI442suG8NqMDVp5xNm/558UXvLlql0qPT7IZgw13zV5+WQGiGseaBVRMI88ocDuR41sx2hWXK4M 5X7AKOgjAVpiyi6cLXE9x/NjRPLImgZ11C9Ig91weaT0eWlD0L9ez9G7fk4OuIZKbhO4z/AnhYN9 XZMT6ercjXWGlaqzGxN5DrAkxY43bzPboKdURODG5Gyuu6kYfS6MhlvhgRfUo2axJA4T5c9bUfdd awYZziyB+cv5K3lLQ/zgJq3vsrCBwDbg7E5gCmArRLXIG0p+2VLpnCLNbfdDmVCg4XZlNIeo26fT vJMRRY5g1GqSS6Z5aJ5lVHi7WIKeIjKGAXu67UZlG+Vi5SNi0hJI4hjy9N0eEQmsg+Ba7N5guomV ESD87ya82Bsyl9/2eRf26OKQuqWbKpukfqbuJVU0Qr6sxpA1mN4RbTBFNHovyQqydeq9xMxBIoEW KiNjQmyV+BdKu/hWW+mrJLDixtJYaq4bt6V3BGes9uh6NgMPw6MF9CxfczN96Nj6sathXgLsN5SR Nh5KOQF4mPvYdjPIbV5g7h3949mb6EQHiVVlIbRG9oIuAWaLnX96WtldNDCmCegRhbD2ohsrol3d alv3KUV9Ghug5QARAQABtBxGYWIgU3R6IDxmYWJzdHotaXRAeWFob28uZnI+iQJOBBMBCgA4FiEE 4hIWQ72cwQ0rCWXOaA8W9i5jBvYFAmfqLtICGy8FCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQ aA8W9i5jBvYUXRAAjJ0RUs2jt01BLZVeAs31sYi0U4GEiAUxkri9y3dwNYAe43LpIbgv2Oc+HQOe tv68rBUPAAOVkqeAyaKlkcAO5c5dlsbiYMoo/v3JJIMBYVU6ZP2c/29wNd7kP8ur1Sv5LF9GPZmL ikI6b/LnSRU3vZG90IvyokYnYywpxWoHuLun5IdjVCRVX6pxmrasudptMgVk69d9F9gWu363t+JJ RKIsXbrDyPad45w5113ZF2zFViqr4klcE4JD4GmDCpWq4feL0a8x6yaqeqh97Ew+UzxMOzdEvUdM r+lOkd5s4GFWyaegVEZHG7XuT4DqtUZYCB3NaIirQxiOg1pWvkMmFKwbGMLX2bjZ3CJD3OtxuWb5 MPQJzkaEtUBv3IIdrXoJ8ydkrNk1aQv7YG9oiDn7uYvL4lZlk4qwE7lxR34JbKj589vWbjQuX9rk Hhm0Knp2UF3rakBqFUClWTEZrRUQPFU2CInZ0LXfleAXdg1/CTdEDjYRTVCZIsKMwVes+O9nHjuM /r38f+5JxrCWtoLEXCu39ASJkTy5I1qJHQABC2gCuSM7somjKwr3ep8rcdyYjKCeoMtLH5Znzba9 Kd0PLgFulras88ouJwi4X3fUyTK8jOPuxRtHGv8lPccy51GvRUzHTIIOPF8/Awnga5mjPSabvrYH iC4+6HbHU/bJD2Q=
- Delivered-to: jetty-users@xxxxxxxxxxx
- List-archive: <https://www.eclipse.org/mailman/private/jetty-users/>
- List-help: <mailto:jetty-users-request@eclipse.org?subject=help>
- List-subscribe: <https://www.eclipse.org/mailman/listinfo/jetty-users>, <mailto:jetty-users-request@eclipse.org?subject=subscribe>
- List-unsubscribe: <https://www.eclipse.org/mailman/options/jetty-users>, <mailto:jetty-users-request@eclipse.org?subject=unsubscribe>
- User-agent: K-9 Mail for Android
Ok, thank you. I'll try that once jetty12 package works on Debian.
Le 26 juin 2025 08:57:49 GMT+02:00, Lachlan Roberts <lachlan@xxxxxxxxxxx> a écrit :
The snippet would not work in Jetty 12 directly, because Jetty 12.0 supports EE8, EE9 and EE10.
So that WebAppContext class does not exist anymore, you would use something like org.eclipse.jetty.ee8.webapp.WebAppContext
Le jeudi 26 juin 2025 08:26:22 CEST, vous avez écrit :
> Jetty 9 is EOL, you should upgrade to 12.0
> see https://github.com/jetty/jetty.project/issues/7958
Debian stable (bookworm) ships jetty9, so upgrading will be difficult.
Debian testing (trixie) has (jetty9 and) jetty12, but it doesn't startup, maybe because of packaging issues.
Should I understand that you snippet will work fine with jetty12 and that the cause of my issues is jetty9?
> > I don't think that there is an issue with the webapp because with the
> deprecated AllowSymLinkAliasChecker it works.
>
> I would not recommend using AllowSymLinkAliasChecker, it has some security
> issues.
> These issues have been fixed in the SymlinkAllowedResourceAliasChecker.
It look like I don't have choice and have to stick to the deprecated alternative since I can't make SymlinkAllowedResourceAliasChecker work with jetty9.
Regards