Uploaded image for project: 'RichFaces'
  1. RichFaces
  2. RF-1330

Security: event handlers could be invoked for inappropriate drag/accepted types

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Critical
    • Resolution: Done
    • Affects Version/s: 3.2.0
    • Fix Version/s: 3.1.3, 3.2.0
    • Component/s: None
    • Labels:
      None

      Description

      If client validation will be off for D'n'D, than it's possible to D'n'D incompatible things

        Gliffy Diagrams

          Activity

          Hide
          nbelaevski Nick Belaevski added a comment -

          Use:
          DnD.CLIENT_VALIDATION_OFF = true;

          to switch off client validation for testing

          Show
          nbelaevski Nick Belaevski added a comment - Use: DnD.CLIENT_VALIDATION_OFF = true; to switch off client validation for testing
          Hide
          nbelaevski Nick Belaevski added a comment -

          fixed, suggested for 3.1.x

          Show
          nbelaevski Nick Belaevski added a comment - fixed, suggested for 3.1.x
          Hide
          nbelaevski Nick Belaevski added a comment -

          Issue should be verified either for inline e.g. dragListener="#

          {...}

          " or for nested <rich:dragListener> listeners

          Show
          nbelaevski Nick Belaevski added a comment - Issue should be verified either for inline e.g. dragListener="# {...} " or for nested <rich:dragListener> listeners
          Hide
          ilya_shaikovsky Ilya Shaikovsky added a comment -

          commit to 3.1.x please.

          Show
          ilya_shaikovsky Ilya Shaikovsky added a comment - commit to 3.1.x please.

            People

            • Assignee:
              ayanul Aleksej Yanul
              Reporter:
              nbelaevski Nick Belaevski
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development