Selaa lähdekoodia

Add plugin io.spring.nohttp

Joe Grandja 5 vuotta sitten
vanhempi
commit
12d228c089
2 muutettua tiedostoa jossa 13 lisäystä ja 1 poistoa
  1. 6 1
      build.gradle
  2. 7 0
      etc/nohttp/allowlist.lines

+ 6 - 1
build.gradle

@@ -2,7 +2,7 @@ buildscript {
 	dependencies {
 		classpath 'io.spring.gradle:spring-build-conventions:0.0.33.RELEASE'
 		classpath "org.springframework.boot:spring-boot-gradle-plugin:$springBootVersion"
-
+		classpath 'io.spring.nohttp:nohttp-gradle:0.0.5.RELEASE'
 	}
 	repositories {
 		maven { url 'https://repo.spring.io/plugins-snapshot' }
@@ -10,6 +10,7 @@ buildscript {
 	}
 }
 
+apply plugin: 'io.spring.nohttp'
 apply plugin: 'io.spring.convention.root'
 
 group = 'org.springframework.security.experimental'
@@ -26,3 +27,7 @@ subprojects {
 		project.sourceCompatibility = '1.8'
 	}
 }
+
+nohttp {
+	allowlistFile = project.file("etc/nohttp/allowlist.lines")
+}

+ 7 - 0
etc/nohttp/allowlist.lines

@@ -0,0 +1,7 @@
+^http://[^/]*nabble.com.*
+^http://blog.opensecurityresearch.com/.*
+^http://iharder.sourceforge.net/current/java/base64/
+^http://jaspan.com.*
+^http://lists.webappsec.org/.*
+^http://webblaze.cs.berkeley.edu/.*
+^http://www.w3.org/2000/09/xmldsig.*