mirror of https://github.com/apache/lucene.git
c8c9c10023
Unfortunately, as a first start this is very weak protection against e.g. XSS. This is because some 'unsafe-xxx' rules must be present due to the insecurity of angular JS: Until SOLR-13987 is fixed, XSS & co are still easy. |
||
---|---|---|
.. | ||
jetty-http.xml | ||
jetty-https.xml | ||
jetty-https8.xml | ||
jetty-ssl.xml | ||
jetty.xml | ||
webdefault.xml |