About "Parameter Validation Filter"

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

About "Parameter Validation Filter"

Emi Lu
Hello,

There is a topic about Parameter Validation Filter
(TrimTextValidationRule, FailIfNotCanonicalizedValidationRule,
FailIfContainsHTMLValidationRule) for servlet
(https://www.owasp.org/index.php/Parameter_Validation_Filter).

I just want to know that struts2.5.14.1 already have these kinds of
validation set by default and no need to add pvf.xml anymore, right?

Thanks a lot.
Reply | Threaded
Open this post in threaded view
|

Re: About "Parameter Validation Filter"

Lukasz Lenart
2018-02-28 17:55 GMT+01:00 Emi <[hidden email]>:
> Hello,
>
> There is a topic about Parameter Validation Filter (TrimTextValidationRule,
> FailIfNotCanonicalizedValidationRule, FailIfContainsHTMLValidationRule) for
> servlet (https://www.owasp.org/index.php/Parameter_Validation_Filter).
>
> I just want to know that struts2.5.14.1 already have these kinds of
> validation set by default and no need to add pvf.xml anymore, right?

No, I mean, Struts do not perform such validations automatically.


Regards
--
Ɓukasz
+ 48 606 323 122 http://www.lenart.org.pl/

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]