diff options
| author | Thomas Lenz <tlenz@iaik.tugraz.at> | 2017-11-27 12:11:45 +0100 | 
|---|---|---|
| committer | Thomas Lenz <tlenz@iaik.tugraz.at> | 2017-11-27 12:11:45 +0100 | 
| commit | 5f2ad9d48b83d5979b1a147190f5177e3327744a (patch) | |
| tree | 81cfcaae779036292c0fbe2213d22d7bab2fa0d1 /id/ConfigWebTool/src/main | |
| parent | aca73741002d4285492d2b95f88779a14171b4e7 (diff) | |
| download | moa-id-spss-5f2ad9d48b83d5979b1a147190f5177e3327744a.tar.gz moa-id-spss-5f2ad9d48b83d5979b1a147190f5177e3327744a.tar.bz2 moa-id-spss-5f2ad9d48b83d5979b1a147190f5177e3327744a.zip | |
add escaping on some places
Diffstat (limited to 'id/ConfigWebTool/src/main')
| -rw-r--r-- | id/ConfigWebTool/src/main/java/at/gv/egovernment/moa/id/configuration/auth/pvp2/servlets/SLOBackChannelServlet.java | 9 | 
1 files changed, 5 insertions, 4 deletions
| diff --git a/id/ConfigWebTool/src/main/java/at/gv/egovernment/moa/id/configuration/auth/pvp2/servlets/SLOBackChannelServlet.java b/id/ConfigWebTool/src/main/java/at/gv/egovernment/moa/id/configuration/auth/pvp2/servlets/SLOBackChannelServlet.java index 17d3d9e50..f2c95f391 100644 --- a/id/ConfigWebTool/src/main/java/at/gv/egovernment/moa/id/configuration/auth/pvp2/servlets/SLOBackChannelServlet.java +++ b/id/ConfigWebTool/src/main/java/at/gv/egovernment/moa/id/configuration/auth/pvp2/servlets/SLOBackChannelServlet.java @@ -33,6 +33,7 @@ import javax.servlet.ServletException;  import javax.servlet.http.HttpServletRequest;  import javax.servlet.http.HttpServletResponse; +import org.apache.commons.lang.StringEscapeUtils;  import org.opensaml.common.SAMLObject;  import org.opensaml.common.binding.BasicSAMLMessageContext;  import org.opensaml.saml2.binding.encoding.HTTPSOAP11Encoder; @@ -144,19 +145,19 @@ public class SLOBackChannelServlet extends SLOBasicServlet {  		} catch (MessageDecodingException | SecurityException | NoSuchAlgorithmException | ConfigurationException | ValidationException e) {  			log.error("SLO message processing FAILED." , e);			 -			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, e.getMessage()); +			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, StringEscapeUtils.escapeHtml(e.getMessage()));  		} catch (CertificateException e) {  			log.error("SLO message processing FAILED." , e); -			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, e.getMessage()); +			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, StringEscapeUtils.escapeHtml(e.getMessage()));  		} catch (KeyStoreException e) {  			log.error("SLO message processing FAILED." , e); -			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, e.getMessage()); +			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, StringEscapeUtils.escapeHtml(e.getMessage()));  		} catch (MessageEncodingException e) {  			log.error("SLO message processing FAILED." , e); -			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, e.getMessage()); +			response.sendError(HttpServletResponse.SC_INTERNAL_SERVER_ERROR, StringEscapeUtils.escapeHtml(e.getMessage()));  		} | 
