users@glassfish.java.net

Issue 15168: Disallow backslash in resource name

From: Nazrul Islam <nazrul.islam_at_oracle.com>
Date: Tue, 21 Dec 2010 12:28:46 -0800

GlassFish Users,

For GlassFish Server Open Source Edition 3.1 release, we are planning to
not-allow backslash (\) in resource names. Please let me know if you
think this would be problem for you.

*Background
*"In the current implementation, there seem to be an issue in grizzly
due to which resources (jdbc/connector/mail/admin-object/custom/jndi)
that has "\" in their names result in failures and hence REST/GUI is not
able to display the resources list properly in admin console." [Jagadish]

"In general, allowing backslashes as they are (not replacing with
slashes) in URLs, could lead to security problems. In some OSes "\"
could be a part of file name, in Windows it's a path separator. So it's
potential hole in security. " [Oleksiy]

Thanks.

*References
*

http://java.net/jira/browse/GLASSFISH-15168
http://java.net/jira/browse/GLASSFISH-13348
http://java.net/jira/browse/GLASSFISH-14441

-- 
Nazrul Islam   -   (408) 276-6468   -   Oracle