Yes, you need the keys to the kingdom (the ability to deploy compiled Java code into the active application's classpath) in order to use the "exploit". If you can accomplish that, the ability to provide your own component actions is a footnote compared to what you could accomplish otherways.
On Sat, Mar 7, 2009 at 11:39 AM, Otho <taa...@googlemail.com> wrote: > If you revert to the official jar, how is your ComponentAction still there? > > And I don't actually understand, what the possible attack vector would be. > -- Howard M. Lewis Ship Creator Apache Tapestry and Apache HiveMind --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscr...@tapestry.apache.org For additional commands, e-mail: users-h...@tapestry.apache.org