Commit 56b42816 authored by Derek DeMoro's avatar Derek DeMoro Committed by derek

JM-1049 - Fix small security issue.

git-svn-id: http://svn.igniterealtime.org/svn/repos/openfire/trunk@8160 b35dd754-fafc-0310-a699-88a17e54d16e
parent 5de49736
...@@ -24,7 +24,8 @@ ...@@ -24,7 +24,8 @@
<init-param> <init-param>
<param-name>excludes</param-name> <param-name>excludes</param-name>
<param-value> <param-value>
login.jsp,index.jsp?logout=true,setup/index.jsp,setup/setup-,.gif,.png,error-serverdown.jsp</param-value> login.jsp,index.jsp?logout=true,setup/index.jsp,setup/setup-,.gif,.png,error-serverdown.jsp
</param-value>
</init-param> </init-param>
</filter> </filter>
...@@ -83,6 +84,12 @@ ...@@ -83,6 +84,12 @@
<url-pattern>/*</url-pattern> <url-pattern>/*</url-pattern>
</filter-mapping> </filter-mapping>
<filter-mapping>
<filter-name>AuthCheck</filter-name>
<servlet-name>dwr-invoker</servlet-name>
</filter-mapping>
<listener> <listener>
<listener-class>org.jivesoftware.openfire.XMPPContextListener</listener-class> <listener-class>org.jivesoftware.openfire.XMPPContextListener</listener-class>
</listener> </listener>
...@@ -103,7 +110,7 @@ ...@@ -103,7 +110,7 @@
<servlet-name>dwr-invoker</servlet-name> <servlet-name>dwr-invoker</servlet-name>
<servlet-class>uk.ltd.getahead.dwr.DWRServlet</servlet-class> <servlet-class>uk.ltd.getahead.dwr.DWRServlet</servlet-class>
</servlet> </servlet>
<servlet> <servlet>
<servlet-name>PluginIconServlet</servlet-name> <servlet-name>PluginIconServlet</servlet-name>
<servlet-class>org.jivesoftware.openfire.container.PluginIconServlet</servlet-class> <servlet-class>org.jivesoftware.openfire.container.PluginIconServlet</servlet-class>
...@@ -122,7 +129,7 @@ ...@@ -122,7 +129,7 @@
<url-pattern>/getFavicon</url-pattern> <url-pattern>/getFavicon</url-pattern>
</servlet-mapping> </servlet-mapping>
<servlet-mapping> <servlet-mapping>
<servlet-name>PluginIconServlet</servlet-name> <servlet-name>PluginIconServlet</servlet-name>
<url-pattern>/geticon</url-pattern> <url-pattern>/geticon</url-pattern>
</servlet-mapping> </servlet-mapping>
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment