From e22eec55bf0815dd1c303ac5fb1c6e6f211a70f0 Mon Sep 17 00:00:00 2001 From: "Christopher Lott (cl778h)" Date: Wed, 25 Oct 2017 09:55:06 -0400 Subject: Repair security filters Revise app web.xml to remove typo in Java package name. Also drop unneeded test class. Issue: PORTAL-135 Change-Id: I49662928c5eed38520e9a9c5f839385148aef0fa Signed-off-by: Christopher Lott (cl778h) --- .../analytics/controller/ActionHandler.java | 4 +- .../portalsdk/analytics/model/ReportHandler.java | 3 +- .../analytics/model/runtime/ChartD3Helper.java | 18 ++-- .../epsdk-app-os/src/main/webapp/WEB-INF/web.xml | 2 +- .../onap/portalsdk/core/util/EncDecUtilTest.java | 109 --------------------- ecomp-sdk/pom.xml | 13 +++ 6 files changed, 27 insertions(+), 122 deletions(-) delete mode 100644 ecomp-sdk/epsdk-core/src/main/java/org/onap/portalsdk/core/util/EncDecUtilTest.java diff --git a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/controller/ActionHandler.java b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/controller/ActionHandler.java index 36c9d526..ba455899 100644 --- a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/controller/ActionHandler.java +++ b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/controller/ActionHandler.java @@ -1949,12 +1949,12 @@ public class ActionHandler extends org.onap.portalsdk.analytics.RaptorObject { logger.debug(EELFLoggerDelegate.debugLogger, ("Command Executed ")); //Connection connection = DbUtils.getConnection(); Enumeration enum1 = rr.getParamKeys(); - String value = "", key = ""; + String value = ""; String paramStr = ""; StringBuffer paramBuffer = new StringBuffer(); if(enum1!=null) { for (; enum1.hasMoreElements();) { - key = (String) enum1.nextElement(); + String key = (String) enum1.nextElement(); value = rr.getParamValue(key); paramBuffer.append(key+":"+value+" "); } diff --git a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/ReportHandler.java b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/ReportHandler.java index b4c6faac..0afd354e 100644 --- a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/ReportHandler.java +++ b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/ReportHandler.java @@ -167,6 +167,7 @@ import org.onap.portalsdk.analytics.xmlobj.Reports; import org.onap.portalsdk.analytics.xmlobj.SemaphoreList; import org.onap.portalsdk.analytics.xmlobj.SemaphoreType; import org.onap.portalsdk.core.logging.logic.EELFLoggerDelegate; +import org.owasp.esapi.ESAPI; import com.lowagie.text.Document; import com.lowagie.text.Paragraph; @@ -3712,7 +3713,7 @@ public class ReportHandler extends org.onap.portalsdk.analytics.RaptorObject { //strBuf.append("Run-time Parameters\n"); } csvOut.print("\"" + value.getId() +":" + "\","); - valueName = nvl(value.getName()); + valueName = ESAPI.encoder().canonicalize(nvl(value.getName())); if(valueName.indexOf("~")!= -1 && valueName.startsWith("(")) { csvOut.print("\"'" + valueName.replaceAll("~",",")+ "'\","); } else { diff --git a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/runtime/ChartD3Helper.java b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/runtime/ChartD3Helper.java index 1a8da8d0..f5c641a4 100644 --- a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/runtime/ChartD3Helper.java +++ b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/model/runtime/ChartD3Helper.java @@ -61,6 +61,7 @@ import java.util.regex.Pattern; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpSession; +import org.apache.commons.lang.StringUtils; import org.apache.commons.lang.time.DateUtils; import org.onap.portalsdk.analytics.error.RaptorException; import org.onap.portalsdk.analytics.model.ReportHandler; @@ -1932,29 +1933,28 @@ public class ChartD3Helper { wholeScript.append("