Skip to content

Improved: Sanitize all widget xml ressource location - #1552

Open
nmalin wants to merge 1 commit into
apache:trunkfrom
nmalin:SanitizeWidgetFlexibleLocation
Open

Improved: Sanitize all widget xml ressource location#1552
nmalin wants to merge 1 commit into
apache:trunkfrom
nmalin:SanitizeWidgetFlexibleLocation

Conversation

@nmalin

@nmalin nmalin commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

When you load dynamically an XML file to a widget model you need to follow the security rule

  • a location from component (component://) without other url or '..'
  • or if not a component, the string path is present on an allowed path in security.properties : allowFilePaths

When you load dynamically an XML file to a widget model you need to follow the security rule

* location from component (component://) without other url or '..'
* if not a component, the string path is present on an allowed path in security.properties : allowFilePaths
ashishvijaywargiya added a commit that referenced this pull request Aug 14, 2026
…owlist (#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Adds unit tests for the new checks.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - #1552

PR from @Krishnauprit18 - #1586
ashishvijaywargiya added a commit to ashishvijaywargiya/ofbiz-framework that referenced this pull request Aug 14, 2026
…owlist (apache#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - apache#1552

PR from @Krishnauprit18 - apache#1586

(cherry picked from commit 4afb9c9)
ashishvijaywargiya added a commit to ashishvijaywargiya/ofbiz-framework that referenced this pull request Aug 14, 2026
…owlist (apache#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - apache#1552

PR from @Krishnauprit18 - apache#1586

(cherry picked from commit 4afb9c9)
ashishvijaywargiya added a commit to ashishvijaywargiya/ofbiz-framework that referenced this pull request Aug 14, 2026
…owlist (apache#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - apache#1552

PR from @Krishnauprit18 - apache#1586

(cherry picked from commit 4afb9c9)
@ashishvijaywargiya

Copy link
Copy Markdown
Contributor

Hello @nmalin,

Your changes have been merged using this PR - #1654

Thank you for your kind support.

Please close this PR whenever you can.

Thanks,
Ashish

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants