Branch: refs/heads/stable-16.4.x
Home:
https://github.com/xwiki/xwiki-platform
Commit: e1a811896a1ffd6aef349c5c74ceb4f378359cb2
https://github.com/xwiki/xwiki-platform/commit/e1a811896a1ffd6aef349c5c74ce…
Author: Michael Hamann <michael.hamann(a)xwiki.com>
Date: 2025-02-20 (Thu, 20 Feb 2025)
Changed paths:
M
xwiki-platform-core/xwiki-platform-oldcore/src/main/java/com/xpn/xwiki/internal/objects/classes/ImplicitlyAllowedValuesDBListQueryBuilder.java
M
xwiki-platform-core/xwiki-platform-oldcore/src/test/java/com/xpn/xwiki/internal/objects/classes/ImplicitlyAllowedValuesDBListQueryBuilderTest.java
Log Message:
-----------
XWIKI-22811: Validate field names in DBList queries
* Ensure that the specified fields are actually valid field names
* Don't allow password and email fields
* Add tests
(cherry picked from commit f2ca8649cba2ed3765061660bf5c7f801afa0b24)
To unsubscribe from these emails, change your notification settings at
https://github.com/xwiki/xwiki-platform/settings/notifications