JBoss development,
A new message was posted in the thread "Security problems with
org.jboss.test:jboss-test 1.1.5.GA":
http://community.jboss.org/message/530170#530170
Author : Ales Justin
Profile :
http://community.jboss.org/people/alesj
Message:
--------------------------------------------------------------
I think we should try to figure out the privileged block in the code that is being tested
(and I am presuming AOP).
No, as you can see, in this case it's the test class
that needs to read off System properties.
I would simply suspend the SM for this Sys props invocation, only to restore it to
potentially indentify any AOP missing blocks Anil is talking about.
--------------------------------------------------------------
To reply to this message visit the message page:
http://community.jboss.org/message/530170#530170