Uploaded image for project: 'Sakai'
  1. Sakai
  2. SAK-23400

Login builds path to skin CSS in an unsafe way

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: RESOLVED
    • Priority: Major
    • Resolution: Won't Fix
    • Affects Version/s: 10.0
    • Fix Version/s: None
    • Component/s: Login
    • Labels:
      None

      Description

      In the files login-authn-tool/tool/src/java/org/sakaiproject/login/tool/AuthnPortal.java and login/login-tool/tool/src/java/org/sakaiproject/login/tool/SkinnableLogin.java, the "skin.default" property is fetched and used directly to build a path to tool.css which may not be correct since the portal uses new rules for building skin paths in 2.9.

        Gliffy Diagrams

          Zeplin

            Attachments

              Issue Links

                Activity

                  People

                  Assignee:
                  maintenanceteam Core Team
                  Reporter:
                  daveadams David Adams
                  Votes:
                  0 Vote for this issue
                  Watchers:
                  2 Start watching this issue

                    Dates

                    Created:
                    Updated:
                    Resolved:

                      Git Integration