Skip to content

Commit 284066b

Browse files
authored
Merge pull request #707 from kwwall/issue-620
Issue 620 - Move public static final Strings and enum from DefaultSecurityConfiguration to PropNames
2 parents 3ce4121 + acae408 commit 284066b

19 files changed

+657
-288
lines changed

pom.xml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -140,7 +140,7 @@
140140
<version.powermock>2.0.9</version.powermock>
141141
<version.spotbugs>4.7.0</version.spotbugs>
142142
<version.findsecbugs>1.12.0</version.findsecbugs>
143-
<version.spotbugs.maven>4.6.0.0</version.spotbugs.maven>
143+
<version.spotbugs.maven>4.7.0.0</version.spotbugs.maven>
144144
<version.surefire>3.0.0-M6</version.surefire>
145145
<project.java.target>1.8</project.java.target>
146146
<!-- TODO: Be sure to update. Should be date of previous official release -->
@@ -426,7 +426,7 @@
426426
<plugin>
427427
<groupId>org.codehaus.mojo</groupId>
428428
<artifactId>versions-maven-plugin</artifactId>
429-
<version>2.10.0</version>
429+
<version>2.11.0</version>
430430
<configuration>
431431
<rulesUri>file:${project.basedir}/versionRuleset.xml</rulesUri>
432432
</configuration>
@@ -439,7 +439,7 @@
439439
<plugin>
440440
<groupId>org.cyclonedx</groupId>
441441
<artifactId>cyclonedx-maven-plugin</artifactId>
442-
<version>2.6.1</version>
442+
<version>2.7.0</version>
443443
<executions>
444444
<execution>
445445
<phase>package</phase>

src/examples/java/PersistedEncryptedData.java

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,6 @@
44
import org.owasp.esapi.errors.*;
55
import org.owasp.esapi.codecs.*;
66
import javax.servlet.ServletRequest;
7-
import org.apache.log4j.Logger;
87

98
/** A slightly more complex example showing encoding encrypted data and writing
109
* it out to a file. This is very similar to the example in the ESAPI User

src/main/java/org/owasp/esapi/PropNames.java

Lines changed: 201 additions & 0 deletions
Large diffs are not rendered by default.

src/main/java/org/owasp/esapi/crypto/KeyDerivationFunction.java

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
import org.owasp.esapi.Logger;
2222
import org.owasp.esapi.errors.ConfigurationException;
2323
import org.owasp.esapi.errors.EncryptionException;
24-
import org.owasp.esapi.reference.DefaultSecurityConfiguration;
24+
import static org.owasp.esapi.PropNames.KDF_PRF_ALG;
2525
import org.owasp.esapi.util.ByteConversionUtil;
2626

2727
/**
@@ -133,7 +133,7 @@ public KeyDerivationFunction() {
133133
if ( ! KeyDerivationFunction.isValidPRF(prfName) ) {
134134
throw new ConfigurationException("Algorithm name " + prfName +
135135
" not a valid algorithm name for property " +
136-
DefaultSecurityConfiguration.KDF_PRF_ALG);
136+
KDF_PRF_ALG);
137137
}
138138
prfAlg_ = prfName;
139139
}
@@ -159,8 +159,7 @@ static int getDefaultPRFSelection() {
159159
}
160160
}
161161
throw new ConfigurationException("Algorithm name " + prfName +
162-
" not a valid algorithm name for property " +
163-
DefaultSecurityConfiguration.KDF_PRF_ALG);
162+
" not a valid algorithm name for property " + KDF_PRF_ALG);
164163
}
165164

166165
/**

src/main/java/org/owasp/esapi/errors/EnterpriseSecurityException.java

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,7 @@
1818
import org.owasp.esapi.ESAPI;
1919
import org.owasp.esapi.Logger;
2020

21-
// At some point, all these property names will be moved to a new class named
22-
// org.owasp.esapi.PropNames
23-
// but until then, while this is an ugly kludge, we are importing it via a
24-
// reference implementation class until we have a chance to clean it up.
25-
// (Note: kwwall's Bitbucket code already has that class.)
26-
import static org.owasp.esapi.reference.DefaultSecurityConfiguration.DISABLE_INTRUSION_DETECTION;
21+
import static org.owasp.esapi.PropNames.DISABLE_INTRUSION_DETECTION;
2722

2823

2924
/**

src/main/java/org/owasp/esapi/logging/java/JavaLogFactory.java

Lines changed: 14 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,14 @@
3333
import org.owasp.esapi.logging.cleaning.CompositeLogScrubber;
3434
import org.owasp.esapi.logging.cleaning.LogScrubber;
3535
import org.owasp.esapi.logging.cleaning.NewlineLogScrubber;
36-
import org.owasp.esapi.reference.DefaultSecurityConfiguration;
36+
37+
import static org.owasp.esapi.PropNames.LOG_ENCODING_REQUIRED;
38+
import static org.owasp.esapi.PropNames.LOG_USER_INFO;
39+
import static org.owasp.esapi.PropNames.LOG_CLIENT_INFO;
40+
import static org.owasp.esapi.PropNames.LOG_APPLICATION_NAME;
41+
import static org.owasp.esapi.PropNames.APPLICATION_NAME;
42+
import static org.owasp.esapi.PropNames.LOG_SERVER_IP;
43+
3744
/**
3845
* LogFactory implementation which creates JAVA supporting Loggers.
3946
*
@@ -55,15 +62,15 @@ public class JavaLogFactory implements LogFactory {
5562
private static JavaLogBridge LOG_BRIDGE;
5663

5764
static {
58-
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_ENCODING_REQUIRED);
65+
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(LOG_ENCODING_REQUIRED);
5966
JAVA_LOG_SCRUBBER = createLogScrubber(encodeLog);
6067

6168

62-
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_USER_INFO);
63-
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_CLIENT_INFO);
64-
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_APPLICATION_NAME);
65-
String appName = ESAPI.securityConfiguration().getStringProp(DefaultSecurityConfiguration.APPLICATION_NAME);
66-
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_SERVER_IP);
69+
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_USER_INFO);
70+
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_CLIENT_INFO);
71+
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(LOG_APPLICATION_NAME);
72+
String appName = ESAPI.securityConfiguration().getStringProp(APPLICATION_NAME);
73+
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(LOG_SERVER_IP);
6774
JAVA_LOG_APPENDER = createLogAppender(logUserInfo, logClientInfo, logServerIp, logApplicationName, appName);
6875

6976
Map<Integer, JavaLogLevelHandler> levelLookup = new HashMap<>();

src/main/java/org/owasp/esapi/logging/log4j/Log4JLogFactory.java

Lines changed: 14 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,14 @@
2929
import org.owasp.esapi.logging.cleaning.CompositeLogScrubber;
3030
import org.owasp.esapi.logging.cleaning.LogScrubber;
3131
import org.owasp.esapi.logging.cleaning.NewlineLogScrubber;
32-
import org.owasp.esapi.reference.DefaultSecurityConfiguration;
32+
33+
import static org.owasp.esapi.PropNames.LOG_ENCODING_REQUIRED;
34+
import static org.owasp.esapi.PropNames.LOG_USER_INFO;
35+
import static org.owasp.esapi.PropNames.LOG_CLIENT_INFO;
36+
import static org.owasp.esapi.PropNames.LOG_APPLICATION_NAME;
37+
import static org.owasp.esapi.PropNames.APPLICATION_NAME;
38+
import static org.owasp.esapi.PropNames.LOG_SERVER_IP;
39+
3340
/**
3441
* LogFactory implementation which creates Log4J supporting Loggers.
3542
*
@@ -48,15 +55,15 @@ public class Log4JLogFactory implements LogFactory {
4855
private static Log4JLogBridge LOG_BRIDGE;
4956

5057
static {
51-
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_ENCODING_REQUIRED);
58+
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(LOG_ENCODING_REQUIRED);
5259
Log4J_LOG_SCRUBBER = createLogScrubber(encodeLog);
5360

5461

55-
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_USER_INFO);
56-
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_CLIENT_INFO);
57-
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_APPLICATION_NAME);
58-
String appName = ESAPI.securityConfiguration().getStringProp(DefaultSecurityConfiguration.APPLICATION_NAME);
59-
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_SERVER_IP);
62+
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_USER_INFO);
63+
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_CLIENT_INFO);
64+
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(LOG_APPLICATION_NAME);
65+
String appName = ESAPI.securityConfiguration().getStringProp(APPLICATION_NAME);
66+
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(LOG_SERVER_IP);
6067
Log4J_LOG_APPENDER = createLogAppender(logUserInfo, logClientInfo, logServerIp, logApplicationName, appName);
6168

6269
Map<Integer, Log4JLogLevelHandler> levelLookup = new HashMap<>();

src/main/java/org/owasp/esapi/logging/log4j/Log4JLoggerFactory.java

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,13 @@
2020
import org.owasp.esapi.ESAPI;
2121
import org.owasp.esapi.logging.appender.LogAppender;
2222
import org.owasp.esapi.logging.cleaning.LogScrubber;
23-
import org.owasp.esapi.reference.DefaultSecurityConfiguration;
23+
24+
import static org.owasp.esapi.PropNames.LOG_ENCODING_REQUIRED;
25+
import static org.owasp.esapi.PropNames.LOG_USER_INFO;
26+
import static org.owasp.esapi.PropNames.LOG_CLIENT_INFO;
27+
import static org.owasp.esapi.PropNames.LOG_APPLICATION_NAME;
28+
import static org.owasp.esapi.PropNames.APPLICATION_NAME;
29+
import static org.owasp.esapi.PropNames.LOG_SERVER_IP;
2430

2531
/**
2632
* Service Provider Interface implementation that can be provided as the org.apache.log4j.spi.LoggerFactory reference in a Log4J configuration.
@@ -37,14 +43,14 @@ public class Log4JLoggerFactory implements LoggerFactory {
3743
private static LogScrubber LOG4J_LOG_SCRUBBER;
3844

3945
static {
40-
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_ENCODING_REQUIRED);
46+
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(LOG_ENCODING_REQUIRED);
4147
LOG4J_LOG_SCRUBBER = Log4JLogFactory.createLogScrubber(encodeLog);
4248

43-
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_USER_INFO);
44-
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_CLIENT_INFO);
45-
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_APPLICATION_NAME);
46-
String appName = ESAPI.securityConfiguration().getStringProp(DefaultSecurityConfiguration.APPLICATION_NAME);
47-
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_SERVER_IP);
49+
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_USER_INFO);
50+
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_CLIENT_INFO);
51+
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(LOG_APPLICATION_NAME);
52+
String appName = ESAPI.securityConfiguration().getStringProp(APPLICATION_NAME);
53+
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(LOG_SERVER_IP);
4854
LOG4J_LOG_APPENDER = Log4JLogFactory.createLogAppender(logUserInfo, logClientInfo, logServerIp, logApplicationName, appName);
4955
}
5056

src/main/java/org/owasp/esapi/logging/slf4j/Slf4JLogFactory.java

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,13 @@
2929
import org.owasp.esapi.logging.cleaning.CompositeLogScrubber;
3030
import org.owasp.esapi.logging.cleaning.LogScrubber;
3131
import org.owasp.esapi.logging.cleaning.NewlineLogScrubber;
32-
import org.owasp.esapi.reference.DefaultSecurityConfiguration;
32+
33+
import static org.owasp.esapi.PropNames.LOG_ENCODING_REQUIRED;
34+
import static org.owasp.esapi.PropNames.LOG_USER_INFO;
35+
import static org.owasp.esapi.PropNames.LOG_CLIENT_INFO;
36+
import static org.owasp.esapi.PropNames.LOG_APPLICATION_NAME;
37+
import static org.owasp.esapi.PropNames.APPLICATION_NAME;
38+
import static org.owasp.esapi.PropNames.LOG_SERVER_IP;
3339
import org.slf4j.LoggerFactory;
3440
/**
3541
* LogFactory implementation which creates SLF4J supporting Loggers.
@@ -54,15 +60,15 @@ public class Slf4JLogFactory implements LogFactory {
5460
private static Slf4JLogBridge LOG_BRIDGE;
5561

5662
static {
57-
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_ENCODING_REQUIRED);
63+
boolean encodeLog = ESAPI.securityConfiguration().getBooleanProp(LOG_ENCODING_REQUIRED);
5864
SLF4J_LOG_SCRUBBER = createLogScrubber(encodeLog);
5965

6066

61-
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_USER_INFO);
62-
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_CLIENT_INFO);
63-
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_APPLICATION_NAME);
64-
String appName = ESAPI.securityConfiguration().getStringProp(DefaultSecurityConfiguration.APPLICATION_NAME);
65-
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(DefaultSecurityConfiguration.LOG_SERVER_IP);
67+
boolean logUserInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_USER_INFO);
68+
boolean logClientInfo = ESAPI.securityConfiguration().getBooleanProp(LOG_CLIENT_INFO);
69+
boolean logApplicationName = ESAPI.securityConfiguration().getBooleanProp(LOG_APPLICATION_NAME);
70+
String appName = ESAPI.securityConfiguration().getStringProp(APPLICATION_NAME);
71+
boolean logServerIp = ESAPI.securityConfiguration().getBooleanProp(LOG_SERVER_IP);
6672
SLF4J_LOG_APPENDER = createLogAppender(logUserInfo, logClientInfo, logServerIp, logApplicationName, appName);
6773

6874
Map<Integer, Slf4JLogLevelHandler> levelLookup = new HashMap<>();

0 commit comments

Comments
 (0)