diff options
author | Thomas Lenz <tlenz@iaik.tugraz.at> | 2017-11-13 09:38:00 +0100 |
---|---|---|
committer | Thomas Lenz <tlenz@iaik.tugraz.at> | 2017-11-13 09:38:00 +0100 |
commit | fe2a02ec2afcbe2d7b9d59a9969d05923813ffdf (patch) | |
tree | 80ad79cfce7fc1cf70af16279de74b1e0b620e68 /id/server/modules/module-monitoring/src/main/java | |
parent | 6c9f624713895a08fd8c89ed3b86acfe149e6229 (diff) | |
download | moa-id-spss-fe2a02ec2afcbe2d7b9d59a9969d05923813ffdf.tar.gz moa-id-spss-fe2a02ec2afcbe2d7b9d59a9969d05923813ffdf.tar.bz2 moa-id-spss-fe2a02ec2afcbe2d7b9d59a9969d05923813ffdf.zip |
fix some open CrossSiteScripting paths
Diffstat (limited to 'id/server/modules/module-monitoring/src/main/java')
-rw-r--r-- | id/server/modules/module-monitoring/src/main/java/at/gv/egovernment/moa/id/auth/servlet/MonitoringController.java | 7 |
1 files changed, 3 insertions, 4 deletions
diff --git a/id/server/modules/module-monitoring/src/main/java/at/gv/egovernment/moa/id/auth/servlet/MonitoringController.java b/id/server/modules/module-monitoring/src/main/java/at/gv/egovernment/moa/id/auth/servlet/MonitoringController.java index b232b9512..fdc1c9cc1 100644 --- a/id/server/modules/module-monitoring/src/main/java/at/gv/egovernment/moa/id/auth/servlet/MonitoringController.java +++ b/id/server/modules/module-monitoring/src/main/java/at/gv/egovernment/moa/id/auth/servlet/MonitoringController.java @@ -30,6 +30,7 @@ import javax.servlet.ServletException; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; +import org.apache.commons.lang.StringEscapeUtils; import org.springframework.beans.factory.annotation.Autowired; import org.springframework.stereotype.Controller; import org.springframework.web.bind.annotation.RequestMapping; @@ -58,11 +59,9 @@ public class MonitoringController { throws ServletException, IOException{ if (authConfig.isMonitoringActive()) { - Logger.debug("Monitoring Servlet received request"); - - + Logger.debug("Monitoring Servlet received request"); + String modulename = StringEscapeUtils.escapeHtml(req.getParameter(REQUEST_ATTR_MODULE)); - String modulename = req.getParameter(REQUEST_ATTR_MODULE); if (MiscUtil.isEmpty(modulename)) { List<String> error = tests.executeTests(); |