RFR: 8157716: jdk.internal.loader.ClassLoaders.addURLToUCP() should return converted real path URL
Alan Bateman
Alan.Bateman at oracle.com
Wed May 25 19:14:12 UTC 2016
On 25/05/2016 20:04, Martin Buchholz wrote:
> :
>
> Also, I'm sure your security experts have already considered the
> implications of following or not following symlinks when matching
> user-provided paths ...
>
Nothing has changed here and there is always a permission check before
returning a URL to a resource on the class path.
-Alan
More information about the core-libs-dev
mailing list