Details
-
Improvement
-
Status: Closed
-
Normal
-
Resolution: Fixed
-
None
-
None
-
None
-
5
-
Tiger
-
Tiger Sprint 157, Tiger Sprint 158
Description
The ResourceServlet (hippo-cms-utilities) currently doesn't perform authentication. The CMS uses several instances of the ResourceServlet to serve resources from JAR files. By default those include:
- Angular resources below /angular
- CKEditor resources below /ckeditor
- CMS styling below /skin
Logged-out users should not be able to retrieve these resources through the ResourceServlet.
Attachments
Issue Links
- causes
-
FEBUILD-101 Firefox can't retrieve source map as the map is a protected resource and Firefox doesn't authenticate
- Closed
-
ARCHE-532 Update default web.xml
- Closed