Fix high-severity bug 'application exposed to path traversal attack'
[sdc.git] / utils / webseal-simulator / src / main / webapp / WEB-INF / web.xml
index 7535e1b..a293d3c 100644 (file)
@@ -1,40 +1,46 @@
 <?xml version="1.0" encoding="UTF-8"?>
-<web-app xmlns="http://java.sun.com/xml/ns/javaee" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
-       xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd"
-       version="3.0">
-       
-       <display-name>Archetype Created Web Application</display-name>
-
-       <servlet>
-               <servlet-name>Proxy</servlet-name>
-               <servlet-class>org.openecomp.sdc.webseal.simulator.SdcProxy</servlet-class>
-       </servlet>
-       <servlet-mapping>
-               <servlet-name>Proxy</servlet-name>
-               <url-pattern>/*</url-pattern>
-       </servlet-mapping>
-
-       <servlet>
-               <servlet-name>Login</servlet-name>
-               <servlet-class>org.openecomp.sdc.webseal.simulator.Login</servlet-class>
-       </servlet>
-       <servlet-mapping>
-               <servlet-name>Login</servlet-name>
-               <url-pattern>/login</url-pattern>
-       </servlet-mapping>
-       
-       <servlet>
-               <servlet-name>CreateUser</servlet-name>
-               <servlet-class>org.openecomp.sdc.webseal.simulator.RequestsClient</servlet-class>
-       </servlet>
-       <servlet-mapping>
-               <servlet-name>CreateUser</servlet-name>
-               <url-pattern>/create</url-pattern>
-       </servlet-mapping>
-       
-       <welcome-file-list>
-               <welcome-file>login</welcome-file>
-       </welcome-file-list>
+<web-app xmlns="http://java.sun.com/xml/ns/javaee"
+    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
+    xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_3_0.xsd"
+    version="3.0">
+
+    <display-name>Archetype Created Web Application</display-name>
+
+    <servlet>
+        <servlet-name>Proxy</servlet-name>
+        <servlet-class>org.openecomp.sdc.webseal.simulator.SdcProxy</servlet-class>
+    </servlet>
+    <servlet-mapping>
+        <servlet-name>Proxy</servlet-name>
+        <url-pattern>/*</url-pattern>
+    </servlet-mapping>
+
+    <context-param>
+        <param-name>org.eclipse.jetty.servlet.Default.dirAllowed</param-name>
+        <param-value>false</param-value>
+    </context-param>
+
+    <servlet>
+        <servlet-name>Login</servlet-name>
+        <servlet-class>org.openecomp.sdc.webseal.simulator.Login</servlet-class>
+    </servlet>
+    <servlet-mapping>
+        <servlet-name>Login</servlet-name>
+        <url-pattern>/login</url-pattern>
+    </servlet-mapping>
+
+    <servlet>
+        <servlet-name>CreateUser</servlet-name>
+        <servlet-class>org.openecomp.sdc.webseal.simulator.RequestsClient</servlet-class>
+    </servlet>
+    <servlet-mapping>
+        <servlet-name>CreateUser</servlet-name>
+        <url-pattern>/create</url-pattern>
+    </servlet-mapping>
+
+    <welcome-file-list>
+        <welcome-file>login</welcome-file>
+    </welcome-file-list>
 
 </web-app>