nomadinjax/esapi4cf
If anyone is interested in taking over this project please let me know! I no longer have the time to commit to it as my role has changed much since I took this over. This project deserves someone who can devote the necessary time to it! OWASP Enterprise Security API (ESAPI) for ColdFusion/CFML Project
ColdFusionBSD-3-Clause
Issues
- 1
Going to assume this project is dead?
#65 opened by KrunchMuffin - 0
Ensure all SafeSession methods access the CF session scope, not J2EE session
#62 opened by nomadinjax - 0
Allow the password complexity rules "magic" number to be configurable in ESAPI.properties, defaulting to 16
#63 opened by nomadinjax - 3
Investigate session invalidation
#44 opened by nomadinjax - 1
- 1
- 0
- 0
- 0
- 0
- 1
- 0
- 1
- 0
- 4
- 3
Need to allow for resource bundling of validation and other textual messages
#31 opened by nomadinjax - 1
- 3
- 0
Add to default Authenticator ability to implement additional authentication types without overriding default method.
#41 opened by nomadinjax - 1
Modify Authenticator and AccessController to isolate data reads/writes to more easily override for DB interaction
#40 opened by nomadinjax - 1
Add log4j as alternative Logger
#54 opened by nomadinjax - 1
- 1
Add getValidBoolean to validator
#49 opened by nomadinjax - 1
- 2
User implementations must be serializable
#47 opened by nomadinjax - 0
User serialization not working in Railo
#52 opened by nomadinjax - 2
- 0
Create AccessController documentation
#51 opened by nomadinjax - 0
- 1
- 1
- 2
Make getESAPI4JVersion cleaner - no try/catch
#45 opened by nomadinjax - 1
- 1
Context must be accounted for in cookie paths
#38 opened by nomadinjax - 0
Get 'UserTest.testLogout' unit test passing
#19 opened by nomadinjax - 0
- 0
- 0
- 2
Railo 4 only: Fix 'Could not initialize class org.owasp.esapi.codecs.Base64' error
#28 opened by nomadinjax - 1
- 1
- 1
- 1
SafeRequest - HTTPParameterName and HTTPParameterValue had hard-coded maxlengths
#36 opened by nomadinjax - 2
getSecurity method needs to be public
#37 opened by nomadinjax - 2
- 1
DefaultSecurityConfiguration exception "Complex object types cannot be converted to simple values." Line 265
#35 opened by nomadinjax - 1
setResourceDirectory value not being picked up
#34 opened by nomadinjax - 1
DefaultValidator#assertIsValidHTTPRequest - error cookie.getValue(), should be httpCookie variable
#33 opened by nomadinjax - 1
FileBasedAuthenticator#login - try/catch around isSecureChannel that will never catch
#32 opened by nomadinjax - 2