[ 
https://issues.apache.org/jira/browse/CXF-7000?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15421176#comment-15421176
 ] 

Ingo Weiss commented on CXF-7000:
---------------------------------

My security concern is thinking that if logging becomes client controlled a 
malicious user can try to abuse this mechanism.

I see what you mean by duplicated interceptors. My line of thought is having 
LiveLogging for debug purposes only and have that being enabled for a short 
period of time. I believe a LoggingInterceptor, extended or not, can be used 
for all kinds of purposes, live debugging not so much.

[~asoldano], any thoughts?

> Allow logging to be enabled on-the-fly
> --------------------------------------
>
>                 Key: CXF-7000
>                 URL: https://issues.apache.org/jira/browse/CXF-7000
>             Project: CXF
>          Issue Type: Improvement
>          Components: Core, logging
>    Affects Versions: 3.1.7
>            Reporter: Ingo Weiss
>
> Allow the logging feature to be enabled on-the-fly without restarting the bus.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to