From a9fffd2555cc45630ec9be9ce44b3f7ab2ed0241 Mon Sep 17 00:00:00 2001 From: sebdet Date: Thu, 8 Oct 2020 13:28:36 +0200 Subject: Remove the Log4j 1.2.15 Remove the log4j 1.2.15 brought by Sigar library + update ESAPI to support slf4J instead of log4j Issue-ID: SDC-3310 Signed-off-by: sebdet Change-Id: I63cee67d113f51dbe82a64c69629c62b47918103 Signed-off-by: sebdet --- asdctool/pom.xml | 4 +++ catalog-be/pom.xml | 39 ++++++++++++++++++++++ catalog-be/src/main/resources/ESAPI.properties | 2 +- catalog-fe/pom.xml | 15 +++++++++ catalog-fe/src/main/resources/ESAPI.properties | 2 +- .../src/test/resources/config/ESAPI.properties | 2 +- common-app-api/pom.xml | 12 +++++++ common-app-logging/pom.xml | 10 ++++-- integration-tests/pom.xml | 6 ++++ pom.xml | 1 + 10 files changed, 88 insertions(+), 5 deletions(-) diff --git a/asdctool/pom.xml b/asdctool/pom.xml index 09e203d881..46fc455112 100644 --- a/asdctool/pom.xml +++ b/asdctool/pom.xml @@ -123,6 +123,10 @@ slf4j-log4j12 org.slf4j + + log4j + log4j + diff --git a/catalog-be/pom.xml b/catalog-be/pom.xml index 5e674fa266..dca521f65b 100644 --- a/catalog-be/pom.xml +++ b/catalog-be/pom.xml @@ -488,6 +488,17 @@ + + org.owasp.esapi + esapi + 2.2.0.0 + + + xerces + xercesImpl + + + org.onap.portal.sdk epsdk-fw @@ -514,6 +525,10 @@ commons-codec commons-codec + + log4j + log4j + @@ -537,6 +552,12 @@ sigar ${sigar.version} compile + + + log4j + log4j + + org.onap.dmaap.messagerouter.dmaapclient @@ -552,6 +573,14 @@ com.fasterxml.jackson.core jackson-core + + log4j + log4j + + + apache-log4j-extras + log4j + @@ -581,6 +610,10 @@ org.slf4j slf4j-log4j12 + + log4j + log4j + @@ -730,6 +763,12 @@ org.onap.sdc.sdc-be-common security-util-lib ${security.util.lib.version} + + + org.springframework.boot + spring-boot-starter-logging + + org.openecomp.sdc.core diff --git a/catalog-be/src/main/resources/ESAPI.properties b/catalog-be/src/main/resources/ESAPI.properties index 1dedfe6739..a1fcdcdece 100644 --- a/catalog-be/src/main/resources/ESAPI.properties +++ b/catalog-be/src/main/resources/ESAPI.properties @@ -75,7 +75,7 @@ ESAPI.Executor=org.owasp.esapi.reference.DefaultExecutor ESAPI.HTTPUtilities=org.owasp.esapi.reference.DefaultHTTPUtilities ESAPI.IntrusionDetector=org.owasp.esapi.reference.DefaultIntrusionDetector # Log4JFactory Requires log4j.xml or log4j.properties in classpath - http://www.laliluna.de/log4j-tutorial.html -ESAPI.Logger=org.owasp.esapi.reference.Log4JLogFactory +ESAPI.Logger=org.owasp.esapi.logging.slf4j.Slf4JLogFactory #ESAPI.Logger=org.owasp.esapi.reference.JavaLogFactory ESAPI.Randomizer=org.owasp.esapi.reference.DefaultRandomizer ESAPI.Validator=org.owasp.esapi.reference.DefaultValidator diff --git a/catalog-fe/pom.xml b/catalog-fe/pom.xml index 5ac590ed61..b9a75353cc 100644 --- a/catalog-fe/pom.xml +++ b/catalog-fe/pom.xml @@ -240,6 +240,11 @@ + + org.owasp.esapi + esapi + 2.2.0.0 + org.onap.portal.sdk epsdk-fw @@ -254,6 +259,10 @@ slf4j-log4j12 org.slf4j + + log4j + log4j + @@ -262,6 +271,12 @@ sigar ${sigar.version} compile + + + log4j + log4j + + diff --git a/catalog-fe/src/main/resources/ESAPI.properties b/catalog-fe/src/main/resources/ESAPI.properties index 1dedfe6739..a1fcdcdece 100644 --- a/catalog-fe/src/main/resources/ESAPI.properties +++ b/catalog-fe/src/main/resources/ESAPI.properties @@ -75,7 +75,7 @@ ESAPI.Executor=org.owasp.esapi.reference.DefaultExecutor ESAPI.HTTPUtilities=org.owasp.esapi.reference.DefaultHTTPUtilities ESAPI.IntrusionDetector=org.owasp.esapi.reference.DefaultIntrusionDetector # Log4JFactory Requires log4j.xml or log4j.properties in classpath - http://www.laliluna.de/log4j-tutorial.html -ESAPI.Logger=org.owasp.esapi.reference.Log4JLogFactory +ESAPI.Logger=org.owasp.esapi.logging.slf4j.Slf4JLogFactory #ESAPI.Logger=org.owasp.esapi.reference.JavaLogFactory ESAPI.Randomizer=org.owasp.esapi.reference.DefaultRandomizer ESAPI.Validator=org.owasp.esapi.reference.DefaultValidator diff --git a/catalog-fe/src/test/resources/config/ESAPI.properties b/catalog-fe/src/test/resources/config/ESAPI.properties index 1dedfe6739..a1fcdcdece 100644 --- a/catalog-fe/src/test/resources/config/ESAPI.properties +++ b/catalog-fe/src/test/resources/config/ESAPI.properties @@ -75,7 +75,7 @@ ESAPI.Executor=org.owasp.esapi.reference.DefaultExecutor ESAPI.HTTPUtilities=org.owasp.esapi.reference.DefaultHTTPUtilities ESAPI.IntrusionDetector=org.owasp.esapi.reference.DefaultIntrusionDetector # Log4JFactory Requires log4j.xml or log4j.properties in classpath - http://www.laliluna.de/log4j-tutorial.html -ESAPI.Logger=org.owasp.esapi.reference.Log4JLogFactory +ESAPI.Logger=org.owasp.esapi.logging.slf4j.Slf4JLogFactory #ESAPI.Logger=org.owasp.esapi.reference.JavaLogFactory ESAPI.Randomizer=org.owasp.esapi.reference.DefaultRandomizer ESAPI.Validator=org.owasp.esapi.reference.DefaultValidator diff --git a/common-app-api/pom.xml b/common-app-api/pom.xml index 5b03dfb940..4dbb6ddd4f 100644 --- a/common-app-api/pom.xml +++ b/common-app-api/pom.xml @@ -17,6 +17,12 @@ org.onap.sdc.sdc-be-common security-util-lib ${security.util.lib.version} + + + org.springframework.boot + spring-boot-starter-logging + + @@ -174,6 +180,12 @@ sigar ${sigar.version} provided + + + log4j + log4j + + diff --git a/common-app-logging/pom.xml b/common-app-logging/pom.xml index 51f959acbd..31d1af3de9 100644 --- a/common-app-logging/pom.xml +++ b/common-app-logging/pom.xml @@ -13,7 +13,6 @@ - javax.servlet javax.servlet-api @@ -41,11 +40,18 @@ provided + + ch.qos.logback + logback-core + ${logback.version} + compile + + ch.qos.logback logback-classic ${logback.version} - provided + compile diff --git a/integration-tests/pom.xml b/integration-tests/pom.xml index 3051c68b11..726bc5b6f0 100644 --- a/integration-tests/pom.xml +++ b/integration-tests/pom.xml @@ -247,6 +247,12 @@ limitations under the License. 3.3 test + + org.apache.logging.log4j + log4j-api + 2.13.1 + test + diff --git a/pom.xml b/pom.xml index 001a98ca83..78d79a80a7 100644 --- a/pom.xml +++ b/pom.xml @@ -497,6 +497,7 @@ Modifications copyright (c) 2018-2019 Nokia 11 11 + true -- cgit 1.2.3-korg