[
https://issues.apache.org/jira/browse/SLING-13337?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115653#comment-18115653
]
Konrad Windszus commented on SLING-13337:
-----------------------------------------
Also Jakarta JSON usually refers to the Spec/API only. The impl previously used
for testing was the Glassfish one....
> Support JSON comments if Johnzon is used as JSON parser
> -------------------------------------------------------
>
> Key: SLING-13337
> URL: https://issues.apache.org/jira/browse/SLING-13337
> Project: Sling
> Issue Type: Improvement
> Components: XSS Protection API
> Reporter: Joerg Hoh
> Assignee: Joerg Hoh
> Priority: Major
> Fix For: XSS Protection API 2.4.12
>
>
> use Johnzon instead of Jakarta JSON, as we use Johnzon in the Sling Starter
> as well.
> Also adding a validation explicitly targetting JSON comments (which Johnzon
> supports) to avoid StackOverflows in the in-depth scanner before the data is
> passed to the JSON parser.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)