]
Jason Greene updated WFLY-84:
-----------------------------
Fix Version/s: 9.0.0.Beta1
(was: 9.0.0.Alpha1)
Jasper using wrong ProtectionDomain for compiled JSP
----------------------------------------------------
Key: WFLY-84
URL:
https://issues.jboss.org/browse/WFLY-84
Project: WildFly
Issue Type: Bug
Components: Web (Undertow)
Reporter: David Lloyd
Assignee: Remy Maucherat
Fix For: 9.0.0.Beta1
Compiled JSPs loaded via JasperLoader appear to be using a different ProtectionDomain
than the rest of the WAR deployment. I think it should probably be using a PD which
contains the permissions from the deployment's ClassLoader, and probably the
CodeSource from the deployment unit from which the JSP file originated. This will ensure
that permissions set via deployment descriptor and/or the management model will take
proper effect.