Skip to content

Restrict widget resource locations to component:// or an explicit allowlist - #1650

Merged
ashishvijaywargiya merged 1 commit into
apache:trunkfrom
ashishvijaywargiya:login-page-widget-fix
Aug 14, 2026
Merged

Restrict widget resource locations to component:// or an explicit allowlist#1650
ashishvijaywargiya merged 1 commit into
apache:trunkfrom
ashishvijaywargiya:login-page-widget-fix

Conversation

@ashishvijaywargiya

@ashishvijaywargiya ashishvijaywargiya commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid, menu, and tree resource locations. Reject any file: scheme location regardless of letter case, reject '..' traversal inside component:// locations, and deny non-component locations by default unless allowed via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request attributes that already exist as trusted ServletContext attributes, which is how a request-controlled value could shadow a webapp's configured decorator location.

Adds unit tests for the new checks.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for your help.

PR from @nmalin - #1552

PR from @Krishnauprit18 - #1586

…owlist

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Adds unit tests for the new checks.
@ashishvijaywargiya
ashishvijaywargiya merged commit 4afb9c9 into apache:trunk Aug 14, 2026
7 checks passed
ashishvijaywargiya added a commit to ashishvijaywargiya/ofbiz-framework that referenced this pull request Aug 14, 2026
…owlist (apache#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - apache#1552

PR from @Krishnauprit18 - apache#1586

(cherry picked from commit 4afb9c9)
ashishvijaywargiya added a commit to ashishvijaywargiya/ofbiz-framework that referenced this pull request Aug 14, 2026
…owlist (apache#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - apache#1552

PR from @Krishnauprit18 - apache#1586

(cherry picked from commit 4afb9c9)
ashishvijaywargiya added a commit to ashishvijaywargiya/ofbiz-framework that referenced this pull request Aug 14, 2026
…owlist (apache#1650)

Add WidgetSecureLocation as a single gatekeeper for screen, form, grid,
menu, and tree resource locations. Reject any file: scheme location
regardless of letter case, reject '..' traversal inside component://
locations, and deny non-component locations by default unless allowed
via the new security.allowFilePaths pattern.

Also stop anonymous JSON request bodies from overriding request
attributes that already exist as trusted ServletContext attributes,
which is how a request-controlled value could shadow a webapp's
configured decorator location.

Thank you Krishna Uprit(@Krishnauprit18) and Nicolas Malin(@nmalin) for
your help.

PR from @nmalin - apache#1552

PR from @Krishnauprit18 - apache#1586

(cherry picked from commit 4afb9c9)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant