[JBoss JIRA] (WFLY-7515) Elytron "expressions-allowed" => false attributes
by Martin Choma (JIRA)
Martin Choma created WFLY-7515:
----------------------------------
Summary: Elytron "expressions-allowed" => false attributes
Key: WFLY-7515
URL: https://issues.jboss.org/browse/WFLY-7515
Project: WildFly
Issue Type: Bug
Components: Security
Affects Versions: 11.0.0.Alpha1
Reporter: Martin Choma
Please change these attributes to {{"expressions-allowed" => true}} if reasonable
{code}
/configurable-sasl-server-factory/protocol
/configurable-sasl-server-factory/server-name
/filesystem-realm/levels
/token-realm/public-key
/token-realm/principal-claim
/token-realm/oauth2-introspection/host-name-verification-policy
/token-realm/oauth2-introspection/introspection-url
/token-realm/oauth2-introspection/client-secret
/token-realm/oauth2-introspection/client-id
/token-realm/oauth2-introspection/public-key
/token-realm/oauth2-introspection/token-realm
/jdbc-realm/principal-query/sql
/jdbc-realm/principal-query/data-source
/jdbc-realm/clear-password-mapper/password-index
/jdbc-realm/bcrypt-mapper/password-index
/jdbc-realm/bcrypt-mapper/salt-index
/jdbc-realm/bcrypt-mapper/iteration-count-index
/jdbc-realm/salted-simple-digest-mapper/algorithm
/jdbc-realm/salted-simple-digest-mapper/password-index
/jdbc-realm/salted-simple-digest-mapper/salt-index
/jdbc-realm/simple-digest-mapper/password-index
/jdbc-realm/scram-mapper/algorithm
/jdbc-realm/scram-mapper/password-index
/jdbc-realm/scram-mapper/salt-index
/jdbc-realm/scram-mapper/iteration-count-index
/security-domain/default-realm
These applies to key-store and key-manager:
*/credential-reference/store
*/credential-reference/alias
*/credential-reference/type
*/credential-reference/clear-text
{code}
These are not marked as capability reference. But seems referencing another service, so not sure if it is issue in these cases:
* /jdbc-realm/principal-query/data-source
* /security-domain/default-realm
* /credential-reference/store
"Collection of primitives" , e.g. LIST of STRING, OBJECT of STRING :
{code}
/configurable-sasl-server-factory/properties
/custom-role-mapper/configuration
/mapped-regex-realm-mapper/realm-map
/x500-attribute-principal-decoder/required-oids
/custom-permission-mapper/configuration
/configurable-http-server-mechanism-factory/properties
/custom-name-rewriter/configuration
/custom-principal-decoder/configuration
/custom-realm-mapper/configuration
/custom-modifiable-realm/configuration
/custom-credential-security-factory/configuration
/custom-role-decoder/configuration
/custom-realm/configuration
{code}
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 8 months
[JBoss JIRA] (WFLY-7499) Elytron "expressions-allowed" => false attributes
by Martin Choma (JIRA)
[ https://issues.jboss.org/browse/WFLY-7499?page=com.atlassian.jira.plugin.... ]
Martin Choma updated WFLY-7499:
-------------------------------
Description:
Please change these attributes to {{"expressions-allowed" => true}} if reasonable
{code}
/configurable-sasl-server-factory/protocol
/configurable-sasl-server-factory/server-name
/filesystem-realm/levels
/token-realm/public-key
/token-realm/principal-claim
/token-realm/oauth2-introspection/host-name-verification-policy
/token-realm/oauth2-introspection/introspection-url
/token-realm/oauth2-introspection/client-secret
/token-realm/oauth2-introspection/client-id
/token-realm/oauth2-introspection/public-key
/token-realm/oauth2-introspection/token-realm
/jdbc-realm/principal-query/sql
/jdbc-realm/principal-query/data-source
/jdbc-realm/clear-password-mapper/password-index
/jdbc-realm/bcrypt-mapper/password-index
/jdbc-realm/bcrypt-mapper/salt-index
/jdbc-realm/bcrypt-mapper/iteration-count-index
/jdbc-realm/salted-simple-digest-mapper/algorithm
/jdbc-realm/salted-simple-digest-mapper/password-index
/jdbc-realm/salted-simple-digest-mapper/salt-index
/jdbc-realm/simple-digest-mapper/password-index
/jdbc-realm/scram-mapper/algorithm
/jdbc-realm/scram-mapper/password-index
/jdbc-realm/scram-mapper/salt-index
/jdbc-realm/scram-mapper/iteration-count-index
/security-domain/default-realm
These applies to key-store and key-manager:
*/credential-reference/store
*/credential-reference/alias
*/credential-reference/type
*/credential-reference/clear-text
{code}
These are not marked as capability reference. But seems referencing another service, so not sure if it is issue in these cases:
* /jdbc-realm/principal-query/data-source
* /security-domain/default-realm
* /credential-reference/store
"Collection of primitives" , e.g. LIST of STRING, OBJECT of STRING :
{code}
/configurable-sasl-server-factory/properties
/custom-role-mapper/configuration
/mapped-regex-realm-mapper/realm-map
/x500-attribute-principal-decoder/required-oids
/custom-permission-mapper/configuration
/configurable-http-server-mechanism-factory/properties
/custom-name-rewriter/configuration
/custom-principal-decoder/configuration
/custom-realm-mapper/configuration
/custom-modifiable-realm/configuration
/custom-credential-security-factory/configuration
/custom-role-decoder/configuration
/custom-realm/configuration
{code}
was:
Please change these attributes to {{"expressions-allowed" => true}} if reasonable
{code}
/configurable-sasl-server-factory/protocol
/configurable-sasl-server-factory/server-name
/filesystem-realm/levels
/token-realm/public-key
/token-realm/principal-claim
/token-realm/oauth2-introspection/host-name-verification-policy
/token-realm/oauth2-introspection/introspection-url
/token-realm/oauth2-introspection/client-secret
/token-realm/oauth2-introspection/client-id
/token-realm/oauth2-introspection/public-key
/token-realm/oauth2-introspection/token-realm
/jdbc-realm/principal-query/sql
/jdbc-realm/principal-query/data-source
/jdbc-realm/clear-password-mapper/password-index
/jdbc-realm/bcrypt-mapper/password-index
/jdbc-realm/bcrypt-mapper/salt-index
/jdbc-realm/bcrypt-mapper/iteration-count-index
/jdbc-realm/salted-simple-digest-mapper/algorithm
/jdbc-realm/salted-simple-digest-mapper/password-index
/jdbc-realm/salted-simple-digest-mapper/salt-index
/jdbc-realm/simple-digest-mapper/password-index
/jdbc-realm/scram-mapper/algorithm
/jdbc-realm/scram-mapper/password-index
/jdbc-realm/scram-mapper/salt-index
/jdbc-realm/scram-mapper/iteration-count-index
/security-domain/default-realm
These applies to key-store and key-manager:
*/credential-reference/store
*/credential-reference/alias
*/credential-reference/type
*/credential-reference/clear-text
{code}
These are not marked as capability reference. But seems referencing another service, so not sure if it is issue in these cases:
* /jdbc-realm/principal-query/data-source
* /security-domain/default-realm
* /credential-reference/store
> Elytron "expressions-allowed" => false attributes
> -------------------------------------------------
>
> Key: WFLY-7499
> URL: https://issues.jboss.org/browse/WFLY-7499
> Project: WildFly
> Issue Type: Bug
> Components: Security
> Affects Versions: 11.0.0.Alpha1
> Reporter: Martin Choma
> Labels: user_experience
>
> Please change these attributes to {{"expressions-allowed" => true}} if reasonable
> {code}
> /configurable-sasl-server-factory/protocol
> /configurable-sasl-server-factory/server-name
> /filesystem-realm/levels
> /token-realm/public-key
> /token-realm/principal-claim
> /token-realm/oauth2-introspection/host-name-verification-policy
> /token-realm/oauth2-introspection/introspection-url
> /token-realm/oauth2-introspection/client-secret
> /token-realm/oauth2-introspection/client-id
> /token-realm/oauth2-introspection/public-key
> /token-realm/oauth2-introspection/token-realm
> /jdbc-realm/principal-query/sql
> /jdbc-realm/principal-query/data-source
> /jdbc-realm/clear-password-mapper/password-index
> /jdbc-realm/bcrypt-mapper/password-index
> /jdbc-realm/bcrypt-mapper/salt-index
> /jdbc-realm/bcrypt-mapper/iteration-count-index
> /jdbc-realm/salted-simple-digest-mapper/algorithm
> /jdbc-realm/salted-simple-digest-mapper/password-index
> /jdbc-realm/salted-simple-digest-mapper/salt-index
> /jdbc-realm/simple-digest-mapper/password-index
> /jdbc-realm/scram-mapper/algorithm
> /jdbc-realm/scram-mapper/password-index
> /jdbc-realm/scram-mapper/salt-index
> /jdbc-realm/scram-mapper/iteration-count-index
> /security-domain/default-realm
> These applies to key-store and key-manager:
> */credential-reference/store
> */credential-reference/alias
> */credential-reference/type
> */credential-reference/clear-text
> {code}
> These are not marked as capability reference. But seems referencing another service, so not sure if it is issue in these cases:
> * /jdbc-realm/principal-query/data-source
> * /security-domain/default-realm
> * /credential-reference/store
> "Collection of primitives" , e.g. LIST of STRING, OBJECT of STRING :
> {code}
> /configurable-sasl-server-factory/properties
> /custom-role-mapper/configuration
> /mapped-regex-realm-mapper/realm-map
> /x500-attribute-principal-decoder/required-oids
> /custom-permission-mapper/configuration
> /configurable-http-server-mechanism-factory/properties
> /custom-name-rewriter/configuration
> /custom-principal-decoder/configuration
> /custom-realm-mapper/configuration
> /custom-modifiable-realm/configuration
> /custom-credential-security-factory/configuration
> /custom-role-decoder/configuration
> /custom-realm/configuration
> {code}
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 8 months
[JBoss JIRA] (DROOLS-355) Do not import com.sun.tools.xjc in drools-core and drools-compiler to fix drools on Karaff/Fuse and/or Java 9
by Geoffrey De Smet (JIRA)
[ https://issues.jboss.org/browse/DROOLS-355?page=com.atlassian.jira.plugin... ]
Geoffrey De Smet reassigned DROOLS-355:
---------------------------------------
Assignee: Mario Fusco (was: Marco Rietveld)
> Do not import com.sun.tools.xjc in drools-core and drools-compiler to fix drools on Karaff/Fuse and/or Java 9
> -------------------------------------------------------------------------------------------------------------
>
> Key: DROOLS-355
> URL: https://issues.jboss.org/browse/DROOLS-355
> Project: Drools
> Issue Type: Task
> Affects Versions: 6.0.0.Final
> Reporter: Geoffrey De Smet
> Assignee: Mario Fusco
> Priority: Blocker
>
> By importing com.sun.tools.xjc, 3 problems arise:
> * OSGi and Karaf trip over it.
> {code}
> [WARNING] No export found to match com.sun.tools.xjc (imported by mvn:org.drools/drools-core/6.0.0.Final)
> {code}
> * JDK 9 will break any java app that uses com.sun.* classes. See Mark Reinhold's Jigsaw presentation at devoxxBE 2013.
> * IBM JDK's etc don't have com.sun.* classes. Why don't they trip over this?
> Why do we have those imports in the first place? Looks like code for old JAXB code - which is hopefully stale now.
> Where do we use it?
> {code}
> Targets
> String 'com.sun.tools.xjc'
> Found usages (38 usages found)
> drools-compiler (7 usages found)
> /home/gdesmet/projects/jboss/droolsjbpm/drools/drools-compiler (1 usage found)
> pom.xml (1 usage found)
> (246: 15) com.sun.tools.xjc.*;resolution:=optional,
> org.drools.compiler.builder.impl (1 usage found)
> KnowledgeBuilderFactoryServiceImpl.java (1 usage found)
> (18: 8) import com.sun.tools.xjc.Options;
> org.drools.compiler.runtime.pipeline.impl (5 usages found)
> DroolsJaxbHelperProviderImpl.java (5 usages found)
> (77: 8) import com.sun.tools.xjc.BadCommandLineException;
> (78: 8) import com.sun.tools.xjc.ErrorReceiver;
> (79: 8) import com.sun.tools.xjc.ModelLoader;
> (80: 8) import com.sun.tools.xjc.Options;
> (81: 8) import com.sun.tools.xjc.model.Model;
> drools-core (2 usages found)
> org.drools.core.builder.conf.impl (2 usages found)
> JaxbConfigurationImpl.java (2 usages found)
> (28: 8) import com.sun.tools.xjc.Language;
> (34: 8) import com.sun.tools.xjc.Options;
> kie-internal (6 usages found)
> /home/gdesmet/projects/jboss/droolsjbpm/droolsjbpm-knowledge/kie-internal (1 usage found)
> pom.xml (1 usage found)
> (27: 15) com.sun.tools.xjc;resolution:=optional,
> org.kie.internal.builder (3 usages found)
> JaxbConfiguration.java (1 usage found)
> (23: 8) import com.sun.tools.xjc.Options;
> KnowledgeBuilderFactory.java (1 usage found)
> (24: 8) import com.sun.tools.xjc.Options;
> KnowledgeBuilderFactoryService.java (1 usage found)
> (24: 8) import com.sun.tools.xjc.Options;
> org.kie.internal.builder.help (2 usages found)
> DroolsJaxbHelperProvider.java (1 usage found)
> (29: 8) import com.sun.tools.xjc.Options;
> KnowledgeBuilderHelper.java (1 usage found)
> (30: 8) import com.sun.tools.xjc.Options;
> knowledge-api (8 usages found)
> org.drools.builder (3 usages found)
> JaxbConfiguration.java (1 usage found)
> (21: 8) import com.sun.tools.xjc.Options;
> KnowledgeBuilderFactory.java (1 usage found)
> (24: 8) import com.sun.tools.xjc.Options;
> KnowledgeBuilderFactoryService.java (1 usage found)
> (24: 8) import com.sun.tools.xjc.Options;
> org.drools.builder.help (3 usages found)
> DroolsJaxbHelperProvider.java (1 usage found)
> (29: 8) import com.sun.tools.xjc.Options;
> KnowledgeBuilderHelper.java (2 usages found)
> (32: 8) import com.sun.tools.xjc.Language;
> (33: 8) import com.sun.tools.xjc.Options;
> org.drools.impl (1 usage found)
> KnowledgeBuilderFactoryServiceImpl.java (1 usage found)
> (16: 8) import com.sun.tools.xjc.Options;
> org.drools.impl.adapters (1 usage found)
> JaxbConfigurationAdapter.java (1 usage found)
> (3: 8) import com.sun.tools.xjc.Options;
> {code}
--
This message was sent by Atlassian JIRA
(v7.2.3#72005)
9 years, 8 months