You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@sling.apache.org by "Konrad Windszus (JIRA)" <ji...@apache.org> on 2016/11/22 15:04:58 UTC

[jira] [Comment Edited] (SLING-5517) Support of startsWith in exclude path of Content Disposition filter

    [ https://issues.apache.org/jira/browse/SLING-5517?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15686969#comment-15686969 ] 

Konrad Windszus edited comment on SLING-5517 at 11/22/16 3:04 PM:
------------------------------------------------------------------

I don't agree with the conclusion here, I think it is a very valid use case to exclude certain parts of the repository from this filter while staying active for all other parts. E.g. I want to disable the filter on {{/apps/myapp/images}} because I know that those persons who have access to that part of the repository are trustworthy. There is currently no way to configure that. Even switching from blacklisting to whitelisting would not help, as you cannot list all other paths of the repository explicitly. How can such a valid use case be solved with the Sling Content Disposition Filter.
[~asanso] Any idea how to solve this without impacting performance too much?


was (Author: kwin):
I don't agree with the conclusion here, I think it is a very valid use case to exclude certain parts of the repository from this filter while staying active for all parts. E.g. I want to disable the filter on {{/apps/myapp/images}} because I know that those persons who have access to that part of the repository are trustworthy. There is currently no way to configure that. Even switching from blacklisting to whitelisting would not help, as you cannot list all other paths of the repository explicitly. How can such a valid use case be solved with the Sling Content Disposition Filter.
[~asanso] Any idea how to solve this without impacting performance too much?

> Support of startsWith in exclude path of Content Disposition filter
> -------------------------------------------------------------------
>
>                 Key: SLING-5517
>                 URL: https://issues.apache.org/jira/browse/SLING-5517
>             Project: Sling
>          Issue Type: Improvement
>          Components: Extensions
>            Reporter: Mandeep Gandhi
>             Fix For: Security 1.0.18
>
>
> Right now exclude path parameter of config of Content Disposition filter takes   specific paths into account. 
> To excluded everything under a give path, an enhancement is required.  



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)