From 25cb8de645e0c016a99a933950bffdc996d74b39 Mon Sep 17 00:00:00 2001 From: Peter Chittum Date: Tue, 30 Jun 2020 08:15:25 +0100 Subject: [PATCH 1/2] added new global variable name to safe resources --- .../sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java | 1 + 1 file changed, 1 insertion(+) diff --git a/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java b/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java index 948f4264aa..4c041e5296 100644 --- a/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java +++ b/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java @@ -296,6 +296,7 @@ public class VfUnescapeElRule extends AbstractVfRule { case "$objecttype": case "$component": case "$remoteaction": + case "$messageservice": return true; default: From 7f0f91f71aac132e3c5ddd9ce397c73f19ebb04e Mon Sep 17 00:00:00 2001 From: Peter Chittum Date: Tue, 30 Jun 2020 08:18:45 +0100 Subject: [PATCH 2/2] added new global variable name to safe resources --- .../sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java b/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java index 4c041e5296..51817b896c 100644 --- a/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java +++ b/pmd-visualforce/src/main/java/net/sourceforge/pmd/lang/vf/rule/security/VfUnescapeElRule.java @@ -296,7 +296,7 @@ public class VfUnescapeElRule extends AbstractVfRule { case "$objecttype": case "$component": case "$remoteaction": - case "$messageservice": + case "$messagechannel": return true; default: