You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@sling.apache.org by ro...@apache.org on 2018/07/12 09:01:34 UTC

svn commit: r28070 - /release/sling/

Author: rombert
Date: Thu Jul 12 09:01:33 2018
New Revision: 28070

Log:
xss 2.0.10

Added:
    release/sling/org.apache.sling.xss-2.0.10-javadoc.jar   (with props)
    release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.asc   (with props)
    release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.md5
    release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.sha1
    release/sling/org.apache.sling.xss-2.0.10-source-release.zip   (with props)
    release/sling/org.apache.sling.xss-2.0.10-source-release.zip.asc   (with props)
    release/sling/org.apache.sling.xss-2.0.10-source-release.zip.md5
    release/sling/org.apache.sling.xss-2.0.10-source-release.zip.sha1
    release/sling/org.apache.sling.xss-2.0.10-sources.jar   (with props)
    release/sling/org.apache.sling.xss-2.0.10-sources.jar.asc   (with props)
    release/sling/org.apache.sling.xss-2.0.10-sources.jar.md5
    release/sling/org.apache.sling.xss-2.0.10-sources.jar.sha1
    release/sling/org.apache.sling.xss-2.0.10.jar   (with props)
    release/sling/org.apache.sling.xss-2.0.10.jar.asc   (with props)
    release/sling/org.apache.sling.xss-2.0.10.jar.md5
    release/sling/org.apache.sling.xss-2.0.10.jar.sha1
    release/sling/org.apache.sling.xss-2.0.10.pom
    release/sling/org.apache.sling.xss-2.0.10.pom.asc   (with props)
    release/sling/org.apache.sling.xss-2.0.10.pom.md5
    release/sling/org.apache.sling.xss-2.0.10.pom.sha1
Removed:
    release/sling/org.apache.sling.xss-2.0.8-javadoc.jar
    release/sling/org.apache.sling.xss-2.0.8-javadoc.jar.asc
    release/sling/org.apache.sling.xss-2.0.8-javadoc.jar.md5
    release/sling/org.apache.sling.xss-2.0.8-javadoc.jar.sha1
    release/sling/org.apache.sling.xss-2.0.8-source-release.zip
    release/sling/org.apache.sling.xss-2.0.8-source-release.zip.asc
    release/sling/org.apache.sling.xss-2.0.8-source-release.zip.md5
    release/sling/org.apache.sling.xss-2.0.8-source-release.zip.sha1
    release/sling/org.apache.sling.xss-2.0.8-sources.jar
    release/sling/org.apache.sling.xss-2.0.8-sources.jar.asc
    release/sling/org.apache.sling.xss-2.0.8-sources.jar.md5
    release/sling/org.apache.sling.xss-2.0.8-sources.jar.sha1
    release/sling/org.apache.sling.xss-2.0.8.jar
    release/sling/org.apache.sling.xss-2.0.8.jar.asc
    release/sling/org.apache.sling.xss-2.0.8.jar.md5
    release/sling/org.apache.sling.xss-2.0.8.jar.sha1
    release/sling/org.apache.sling.xss-2.0.8.pom
    release/sling/org.apache.sling.xss-2.0.8.pom.asc
    release/sling/org.apache.sling.xss-2.0.8.pom.md5
    release/sling/org.apache.sling.xss-2.0.8.pom.sha1

Added: release/sling/org.apache.sling.xss-2.0.10-javadoc.jar
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10-javadoc.jar
------------------------------------------------------------------------------
    svn:mime-type = application/zip

Added: release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.asc
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.asc
------------------------------------------------------------------------------
    svn:mime-type = application/pgp-signature

Added: release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.md5
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.md5 (added)
+++ release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.md5 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+c82006cd860f93fe8eb3043f5119cdca
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.sha1 (added)
+++ release/sling/org.apache.sling.xss-2.0.10-javadoc.jar.sha1 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+44d0cd6f5e7c754f36289ad4da47ee7460e07825
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10-source-release.zip
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10-source-release.zip
------------------------------------------------------------------------------
    svn:mime-type = application/zip

Added: release/sling/org.apache.sling.xss-2.0.10-source-release.zip.asc
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10-source-release.zip.asc
------------------------------------------------------------------------------
    svn:mime-type = application/pgp-signature

Added: release/sling/org.apache.sling.xss-2.0.10-source-release.zip.md5
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10-source-release.zip.md5 (added)
+++ release/sling/org.apache.sling.xss-2.0.10-source-release.zip.md5 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+632b1f698b6d8203a85c8a0a51ed211a
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10-source-release.zip.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10-source-release.zip.sha1 (added)
+++ release/sling/org.apache.sling.xss-2.0.10-source-release.zip.sha1 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+a7a433eef8a51f3e41a899cf53e9a7520db12e5a
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10-sources.jar
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10-sources.jar
------------------------------------------------------------------------------
    svn:mime-type = application/zip

Added: release/sling/org.apache.sling.xss-2.0.10-sources.jar.asc
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10-sources.jar.asc
------------------------------------------------------------------------------
    svn:mime-type = application/pgp-signature

Added: release/sling/org.apache.sling.xss-2.0.10-sources.jar.md5
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10-sources.jar.md5 (added)
+++ release/sling/org.apache.sling.xss-2.0.10-sources.jar.md5 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+054d5bcefdb2ce8e045219669b9957ce
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10-sources.jar.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10-sources.jar.sha1 (added)
+++ release/sling/org.apache.sling.xss-2.0.10-sources.jar.sha1 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+41725f5ac2ca439309c397e5cce6b6c2ae170fbc
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10.jar
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10.jar
------------------------------------------------------------------------------
    svn:mime-type = application/zip

Added: release/sling/org.apache.sling.xss-2.0.10.jar.asc
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10.jar.asc
------------------------------------------------------------------------------
    svn:mime-type = application/pgp-signature

Added: release/sling/org.apache.sling.xss-2.0.10.jar.md5
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10.jar.md5 (added)
+++ release/sling/org.apache.sling.xss-2.0.10.jar.md5 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+ee561046a7b490a233c73f079369fcb0
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10.jar.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10.jar.sha1 (added)
+++ release/sling/org.apache.sling.xss-2.0.10.jar.sha1 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+52440180a01d8942abf540b11f1bdece502f809e
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10.pom
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10.pom (added)
+++ release/sling/org.apache.sling.xss-2.0.10.pom Thu Jul 12 09:01:33 2018
@@ -0,0 +1,298 @@
+<?xml version="1.0"?>
+<!--~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+  ~ Licensed to the Apache Software Foundation (ASF) under one or
+  ~ more contributor license agreements. See the NOTICE file
+  ~ distributed with this work for additional information regarding
+  ~ copyright ownership. The ASF licenses this file to you under the
+  ~ Apache License, Version 2.0 (the "License"); you may not use
+  ~ this file except in compliance with the License. You may obtain
+  ~ a copy of the License at
+  ~
+  ~ http://www.apache.org/licenses/LICENSE-2.0 Unless required by
+  ~ applicable law or agreed to in writing, software distributed
+  ~ under the License is distributed on an "AS IS" BASIS, WITHOUT
+  ~ WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+  ~ See the License for the specific language governing permissions
+  ~ and limitations under the License.
+  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~-->
+<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
+    <modelVersion>4.0.0</modelVersion>
+    <!-- ======================================================================= -->
+    <!-- P A R E N T   P R O J E C T                                             -->
+    <!-- ======================================================================= -->
+    <parent>
+        <groupId>org.apache.sling</groupId>
+        <artifactId>sling</artifactId>
+        <version>30</version>
+        <relativePath />
+    </parent>
+
+    <!-- ======================================================================= -->
+    <!-- P R O J E C T                                                           -->
+    <!-- ======================================================================= -->
+    <artifactId>org.apache.sling.xss</artifactId>
+    <packaging>bundle</packaging>
+    <version>2.0.10</version>
+
+    <name>Apache Sling XSS Protection</name>
+    <description>
+        Apache Sling XSS Protection Bundle providing XSS protection based on the OWASP AntiSamy and OWASP Java Encoder libraries.
+    </description>
+
+    <scm>
+        <connection>scm:git:https://gitbox.apache.org/repos/asf/sling-org-apache-sling-xss.git</connection>
+        <developerConnection>scm:git:https://gitbox.apache.org/repos/asf/sling-org-apache-sling-xss.git</developerConnection>
+        <url>https://gitbox.apache.org/repos/asf?p=sling-org-apache-sling-xss.git</url>
+      <tag>org.apache.sling.xss-2.0.10</tag>
+  </scm>
+
+
+    <!-- ======================================================================= -->
+    <!-- B U I L D                                                               -->
+    <!-- ======================================================================= -->
+    <build>
+        <pluginManagement>
+            <plugins>
+                <plugin>
+                    <!-- Extend RAT configuration from parent pom -->
+                    <groupId>org.apache.rat</groupId>
+                    <artifactId>apache-rat-plugin</artifactId>
+                    <configuration>
+                        <excludes combine.children="append">
+                            <exclude>src/main/resources/ESAPI.properties</exclude>
+                            <exclude>src/main/resources/validation.properties</exclude>
+                        </excludes>
+                    </configuration>
+                </plugin>
+            </plugins>
+        </pluginManagement>
+
+        <plugins>
+            <plugin>
+                <groupId>org.apache.sling</groupId>
+                <artifactId>maven-sling-plugin</artifactId>
+            </plugin>
+            <plugin>
+                <groupId>org.apache.felix</groupId>
+                <artifactId>maven-bundle-plugin</artifactId>
+                <extensions>true</extensions>
+                <configuration>
+                    <instructions>
+                        <Import-Package>
+                            !bsh,
+                            !nu.xom,
+                            !org.apache.log4j.spi,
+                            !org.apache.log4j.xml,
+                            !org.w3c.dom.svg,
+                            !org.apache.avalon.framework.logger,
+                            !org.apache.commons.jxpath.*,
+                            !org.apache.commons.digester.*,
+                            !org.apache.tools.ant.taskdefs,
+                            !org.apache.xml.resolver,
+                            !org.apache.xml.resolver.readers,
+                            !org.apache.xmlgraphics.java2d.color,
+                            !org.apache.log,
+                            !javax.mail.internet,
+                            !javax.servlet.jsp,
+                            !javax.servlet.jsp.tagext,
+                            !sun.io,
+                            *
+                        </Import-Package>
+                        <Private-Package>
+                            org.apache.sling.xss.impl,
+                            org.apache.batik.*,
+                            org.w3c.css.sac,
+                            org.apache.xerces.*,
+                            org.apache.xml.serialize,
+                            org.apache.commons.beanutils.*;-split-package:=merge-first,
+                            org.apache.commons.configuration.*,
+                            org.apache.commons.logging.impl,
+                            org.cyberneko.html.*,
+                        </Private-Package>
+                        <Embed-Dependency>
+                            antisamy;inline=true,
+                            esapi;inline=true,
+                            encoder;inline=true
+                        </Embed-Dependency>
+                        <Sling-Initial-Content>
+                            SLING-INF/content;path:=/libs/sling/xss;overwrite:=true;ignoreImportProviders:=xml
+                        </Sling-Initial-Content>
+                    </instructions>
+                </configuration>
+            </plugin>
+        </plugins>
+    </build>
+
+    <!-- ======================================================================= -->
+    <!-- D E P E N D E N C I E S                                                 -->
+    <!-- ======================================================================= -->
+    <dependencies>
+        <dependency>
+            <groupId>org.owasp.antisamy</groupId>
+            <artifactId>antisamy</artifactId>
+            <version>1.5.7</version>
+            <scope>provided</scope>
+            <exclusions>
+                <exclusion>
+                    <groupId>nu.xom</groupId>
+                    <artifactId>com.springsource.nu.xom</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>bsh</groupId>
+                    <artifactId>bsh</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.axsl.org.w3c.dom.svg</groupId>
+                    <artifactId>svg-dom-java</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>commons-jxpath</groupId>
+                    <artifactId>commons-jxpath</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.apache.commons</groupId>
+                    <artifactId>commons-digester3</artifactId>
+                </exclusion>
+                <!-- #40108 - XSS protection does not work on Java 5 -->
+                <!-- Replace batik-css 1.7 with 1.6. See below.      -->
+                <exclusion>
+                    <groupId>org.apache.xmlgraphics</groupId>
+                    <artifactId>batik-css</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+        <!-- <#40108 - XSS protection does not work on Java 5>  -->
+        <!-- Replace batik-css 1.7 with 1.6 to avoid breaking   -->
+        <!-- the build on Java 5. The batik-css 1.6 pom doesn't -->
+        <!-- have proper dependency metadata, so we need to     -->
+        <!-- reconstruct the full list here.                    -->
+        <!-- TODO: Remove this workaround when we dump Java 5.  -->
+        <dependency>
+            <groupId>org.apache.xmlgraphics</groupId>
+            <artifactId>batik-css</artifactId>
+            <version>1.9.1</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>xml-apis</groupId>
+            <artifactId>xml-apis</artifactId>
+            <version>1.4.01</version>
+            <scope>provided</scope>
+        </dependency>
+        <!-- </#40108 - XSS protection does not work on Java 5> -->
+
+        <dependency>
+            <groupId>org.owasp.esapi</groupId>
+            <artifactId>esapi</artifactId>
+            <version>2.1.0</version>
+            <scope>provided</scope>
+            <exclusions>
+                <exclusion>
+                    <groupId>nu.xom</groupId>
+                    <artifactId>com.springsource.nu.xom</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>bsh</groupId>
+                    <artifactId>bsh</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.axsl.org.w3c.dom.svg</groupId>
+                    <artifactId>svg-dom-java</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>commons-jxpath</groupId>
+                    <artifactId>commons-jxpath</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.apache.commons</groupId>
+                    <artifactId>commons-digester3</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+
+        <dependency>
+            <groupId>org.owasp.encoder</groupId>
+            <artifactId>encoder</artifactId>
+            <scope>provided</scope>
+            <version>1.1.1</version>
+        </dependency>
+
+        <dependency>
+            <groupId>javax.servlet</groupId>
+            <artifactId>javax.servlet-api</artifactId>
+            <scope>provided</scope>
+        </dependency>
+
+        <dependency>
+            <groupId>org.osgi</groupId>
+            <artifactId>osgi.core</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.slf4j</groupId>
+            <artifactId>slf4j-api</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.sling</groupId>
+            <artifactId>org.apache.sling.api</artifactId>
+            <version>2.11.0</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+          <groupId>org.apache.sling</groupId>
+          <artifactId>org.apache.sling.serviceusermapper</artifactId>
+          <version>1.2.0</version>
+          <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>com.google.code.findbugs</groupId>
+            <artifactId>jsr305</artifactId>
+            <version>2.0.0</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.geronimo.specs</groupId>
+            <artifactId>geronimo-json_1.0_spec</artifactId>
+            <version>1.0-alpha-1</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.commons</groupId>
+            <artifactId>commons-lang3</artifactId>
+            <version>3.6</version>
+            <scope>provided</scope>
+        </dependency>
+        <dependency>
+            <groupId>junit</groupId>
+            <artifactId>junit</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.mockito</groupId>
+            <artifactId>mockito-all</artifactId>
+            <version>1.10.19</version>
+            <scope>test</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.powermock</groupId>
+            <artifactId>powermock-api-mockito</artifactId>
+            <version>1.6.5</version>
+            <scope>test</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.sling</groupId>
+            <artifactId>org.apache.sling.commons.johnzon</artifactId>
+            <version>1.0.0</version>
+            <scope>test</scope>
+        </dependency>
+        <dependency>
+            <groupId>org.slf4j</groupId>
+            <artifactId>slf4j-simple</artifactId>
+        </dependency>
+        <dependency>
+            <groupId>org.apache.sling</groupId>
+            <artifactId>org.apache.sling.testing.sling-mock</artifactId>
+            <version>2.2.18</version>
+            <scope>test</scope>
+        </dependency>
+    </dependencies>
+
+</project>

Added: release/sling/org.apache.sling.xss-2.0.10.pom.asc
==============================================================================
Binary file - no diff available.

Propchange: release/sling/org.apache.sling.xss-2.0.10.pom.asc
------------------------------------------------------------------------------
    svn:mime-type = application/pgp-signature

Added: release/sling/org.apache.sling.xss-2.0.10.pom.md5
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10.pom.md5 (added)
+++ release/sling/org.apache.sling.xss-2.0.10.pom.md5 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+2c8a9f89b6aee5d40f86dda3714faf5d
\ No newline at end of file

Added: release/sling/org.apache.sling.xss-2.0.10.pom.sha1
==============================================================================
--- release/sling/org.apache.sling.xss-2.0.10.pom.sha1 (added)
+++ release/sling/org.apache.sling.xss-2.0.10.pom.sha1 Thu Jul 12 09:01:33 2018
@@ -0,0 +1 @@
+a7ad6ac5c5e12f199081b8d78d9658b4d832c8c4
\ No newline at end of file