[ 
https://issues.apache.org/jira/browse/SLING-13337?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115653#comment-18115653
 ] 

Konrad Windszus commented on SLING-13337:
-----------------------------------------

Also Jakarta JSON usually refers to the Spec/API only. The impl previously used 
for testing was the Glassfish one....

> Support JSON comments if Johnzon is used as JSON parser
> -------------------------------------------------------
>
>                 Key: SLING-13337
>                 URL: https://issues.apache.org/jira/browse/SLING-13337
>             Project: Sling
>          Issue Type: Improvement
>          Components: XSS Protection API
>            Reporter: Joerg Hoh
>            Assignee: Joerg Hoh
>            Priority: Major
>             Fix For: XSS Protection API 2.4.12
>
>
> use Johnzon instead of Jakarta JSON, as we use Johnzon in the Sling Starter 
> as well. 
> Also adding a validation explicitly targetting JSON comments (which Johnzon 
> supports) to avoid StackOverflows in the in-depth scanner before the data is 
> passed to the JSON parser.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to