Author: markt Date: Mon Aug 23 17:32:03 2010 New Revision: 988222 URL: http://svn.apache.org/viewvc?rev=988222&view=rev Log: Fix https://issues.apache.org/bugzilla/show_bug.cgi?id=49750 Align WebappClassLoader.validate() implementation with Javadoc and ensure that javax.servlet.* classes can not be loaded by a WebappClassLoader instance. Patch provided by pid.
Modified: tomcat/trunk/java/org/apache/catalina/loader/WebappClassLoader.java tomcat/trunk/webapps/docs/changelog.xml Modified: tomcat/trunk/java/org/apache/catalina/loader/WebappClassLoader.java URL: http://svn.apache.org/viewvc/tomcat/trunk/java/org/apache/catalina/loader/WebappClassLoader.java?rev=988222&r1=988221&r2=988222&view=diff ============================================================================== --- tomcat/trunk/java/org/apache/catalina/loader/WebappClassLoader.java (original) +++ tomcat/trunk/java/org/apache/catalina/loader/WebappClassLoader.java Mon Aug 23 17:32:03 2010 @@ -3206,6 +3206,8 @@ public class WebappClassLoader return false; if (name.startsWith("java.")) return false; + if (name.startsWith("javax.servlet.")) + return false; return true; Modified: tomcat/trunk/webapps/docs/changelog.xml URL: http://svn.apache.org/viewvc/tomcat/trunk/webapps/docs/changelog.xml?rev=988222&r1=988221&r2=988222&view=diff ============================================================================== --- tomcat/trunk/webapps/docs/changelog.xml (original) +++ tomcat/trunk/webapps/docs/changelog.xml Mon Aug 23 17:32:03 2010 @@ -47,6 +47,12 @@ distributable element of web.xml. (kfujino) </fix> <fix> + <bug>47950</bug>: Align <code>WebappClassLoader.validate()</code> + implementation with Javadoc and ensure that <code>javax.servlet.*</code> + classes can not be loaded by a <code>WebappClassLoader</code> instance. + Patch provided by pid. (markt) + </fix> + <fix> <bug>49757</bug>: Correct some generics warnings. Based on a patch provided by Gábor. (markt) </fix> --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org