[seam-dev] Adding a security audit to the Seam QA (release) process

Pete Muir pmuir at redhat.com
Wed Oct 1 07:50:09 EDT 2008


Hi Marc,

Something that we've been discussing is the idea creating a security  
audit checklist that will cover Seam and the ways it interacts with  
the outside world; initially, we want to focus on JSF, Seam Remoting  
(Ajax) and Servlet but we will also consider adding in WS including  
JAX-RS, Wicket, GWT and perhaps others, though these are what I can  
think off. This checklist would then be added to the Seam QA process  
(which is run through at release time).

We were wondering if you would be able to work with us on this? My  
suggestion is, that as you (I hope ;-) have a good understanding of  
the general approaches that could be used to exploit a Seam that you  
would be to work with us both on an initial list of areas to focus on,  
and then help us develop the checklist.

Let us know :)

Pete



More information about the seam-dev mailing list