users@glassfish.java.net

Exposed app server installation directory

From: <glassfish_at_javadesktop.org>
Date: Mon, 30 Mar 2009 17:00:19 PDT

Hi,

I'm using Glassfish as my app server (and using Icefaces in my app) and noticed the other day when attempting to access a URL with xmlhttp at the end, the full installation path of my glassfish server is displayed to the user.

For example:

http://component-showcase.icefaces.org/component-showcase/xmlhttp

Will display the full path to the app server to any user. In itself it doesn't seem a big deal, but the error message should not show full paths for security reasons and its inconsistent with other 404 type errors (I have a custom page to handle 404's but its not being displayed when accessing this URL).

I know the icefaces page show JBoss as their app server, but it also occurs in glassfish, but I'm not sure where the problem lies?
[Message sent by forum member 'michaellshea' (michaellshea)]

http://forums.java.net/jive/thread.jspa?messageID=339744