<workflowRun _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0l2pebQNaPUmG7crv</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0uxyCkj6CGoBn7yyg</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260930</displayName><duration>24065087</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260930</fullDisplayName><id>1164</id><keepLog>false</keepLog><number>1164</number><queueId>63961</queueId><result>SUCCESS</result><timestamp>1790789040596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/site/resources/index.html</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>ec9caee6b1242b8d5893ed5ece0884304d811cb0</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

Smart-Doc parses the sources with QDox and chokes on constructs Silverpeas
relies on, silently reporting a success while producing an incomplete
documentation. Swagger scans the compiled classes by reflection and understands
the JAX-RS annotations, so the whole REST API is covered.

The new core-restapi module gathers the web resources of all the modules into a
single OpenAPI 3.1 document, rendered by Redoc and published on its own at
docs/restapi/core. It produces nothing but that documentation and builds only
with the restapi profile, from which the Smart-Doc plugin is dropped.

All the 217 operations, spread over 168 paths and 86 schemas, are now
documented: a summary, a success response with its schema, and the errors the
endpoint can answer. The responses common to several endpoints are declared once
for all:

  * @Authenticated and @Authorized, besides the security schemes they already
    described, bring the 401 and 403 responses of the protected resources;
  * the 503 is brought by CommonResponsesFilter, applied once the specification
    has been figured out. It cannot come from another meta-annotation of the web
    resources: at class level Swagger returns the responses of the first
    meta-annotation declaring some instead of merging them all, so a second one
    would silently discard the responses of @Authenticated and @Authorized;
  * the recurring 404, 400 and 409 are factored out into the @NotFound,
    @BadRequest and @Conflict annotations of the new annotation.doc package.
    Contrary to the class level one, the method level lookup of Swagger does
    merge, but the description of such an annotation takes precedence over the
    one an endpoint would declare for the same status code, hence an endpoint
    needing another wording must not be annotated.

Documenting the endpoints brought several defects to light, which are fixed
here: the wrong descriptions of the personal space endpoints of SpaceResource, a
test endpoint left over in CipherKeyResource, and the conflicting setters of
AbstractI18NBean for the translations property, which made the scan fail.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>ec9caee6b1242b8d5893ed5ece0884304d811cb0</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</file></path><path><editType>add</editType><file>core-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</file></path><path><editType>add</editType><file>core-restapi/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><commitId>c097c5d943af83fb5ce284ad45b733a9d806b761</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire and missing others that do:

  * an entity whose access is set to XmlAccessType.FIELD was described by its
    getters instead of its fields. SpaceAppearanceEntity came out with two
    properties where six are serialized;
  * a member annotated with @XmlTransient was described all the same.
    PdcAxisValueEntity came out with eleven properties where nine are
    serialized.

The JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,
@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of
a schema, never its visibility. As for the Jackson module bringing that
introspector, it does declare itself to the ServiceLoader, but Swagger never
asks for the modules available in the classpath.

The resolver declared here sets the introspector on a mapper of its own, the
very way the JSON codec of Silverpeas does, so that it applies to the resolution
of the schemas only. Ten business objects were documented that no endpoint ever
answers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the
like -- and they are gone now.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>c097c5d943af83fb5ce284ad45b733a9d806b761</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</affectedPath><commitId>692a545a5347eefc22d5e8f1949b6ce94151f274</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no
parameter to fill that section in, hence the document of its own declared here:
the scan completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published. The published tree is now made of the rendering page, the
specification in both of its formats, and the rendering engine.

Skipping the site altogether looked simpler but isn't an option: the deploy goal
of the site plugin reads the very same maven.site.skip property as its site
goal, so the documentation would have silently stopped being published.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>692a545a5347eefc22d5e8f1949b6ce94151f274</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>078323a23b15cb23bbbcaa797991a709645d0f7d</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, the
routes of the SCIM API not to publish, its filter and its schema resolver, the
WAR whose classes are unpacked, and the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>078323a23b15cb23bbbcaa797991a709645d0f7d</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><commitId>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Gather in core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were duplicated, one copy per project
documenting its REST API, the two being identical but for their package. They
are gathered here, beside the annotations documenting the common errors, in a
package of their own: org.silverpeas.core.rs.doc.

Their name being the same for every project now, the parent POM declares them
once for all, and nothing is left to keep the copies in step.

The counterpart is that core-rs, a module of production, depends on swagger-core
to compile them. The dependency is provided, so nothing of it is shipped, and
neither the filter nor the resolver plays any role at runtime: both are read
when generating the documentation only.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</id><msg>Gather in core-rs what generates the documentation of the REST API</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:17 +0200</date><id>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>5f5891af886c501d82d72d54f15552e3775e0ce7</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)
</comment><date>2026-09-28 14:42:28 +0200</date><id>5f5891af886c501d82d72d54f15552e3775e0ce7</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>018ed026afbb76a9ad52281cd62b8e284b9a914a</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)
</comment><date>2026-09-28 14:42:28 +0200</date><id>018ed026afbb76a9ad52281cd62b8e284b9a914a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</affectedPath><commitId>37283d39cead2166ad9483d373658c2b8e414c95</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)
</comment><date>2026-09-28 14:42:28 +0200</date><id>37283d39cead2166ad9483d373658c2b8e414c95</id><msg>Fix vulnerability #1459</msg><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>b2900e3c4738e94ab34622ee8a48197f7921a09f</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)
</comment><date>2026-09-28 14:42:28 +0200</date><id>b2900e3c4738e94ab34622ee8a48197f7921a09f</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>23acd94a451f35afaf18324777b344292593341b</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.

(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)
</comment><date>2026-09-28 14:42:28 +0200</date><id>23acd94a451f35afaf18324777b344292593341b</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>52843258f403c47fb8a0b51a75295f883fb98eda</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)
</comment><date>2026-09-28 14:42:28 +0200</date><id>52843258f403c47fb8a0b51a75295f883fb98eda</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>df92a06600aedb5b24bad01559165e839421c2b5</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:42:28 +0200</date><id>df92a06600aedb5b24bad01559165e839421c2b5</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>db15a2e30508fb101a2addaf4780cc6479eb9270</commitId><timestamp>1790599436000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:43:56 +0200</date><id>db15a2e30508fb101a2addaf4780cc6479eb9270</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>3f5875d5832af01276050f9ad75a08f7ddb4dd30</commitId><timestamp>1790608429000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:13:49 +0200</date><id>3f5875d5832af01276050f9ad75a08f7ddb4dd30</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>components-restapi/src/site/resources/index.html</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>f2fe8d93d99b4eb77e672c047d22ce154ba94673</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

The new components-restapi module gathers the web resources of the fourteen
applications into a single OpenAPI 3.1 document, rendered by Redoc and published
on its own at docs/restapi/components. It produces nothing but that
documentation and builds only with the restapi profile, from which the Smart-Doc
plugin is dropped.

All the 81 operations, spread over 70 paths and 81 schemas, are now documented.
The twenty-two operations of the almanach are inherited from the calendar
resources of Core and needed nothing: Swagger reads the annotations of the
overridden methods. The others got a summary, a success response with its
schema, and the errors they can answer, the recurring ones coming from the
@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is
brought by CommonResponsesFilter, of which this project has its own copy.

Documenting the endpoints brought several defects to light, which are fixed
here:

  * three of the four folder endpoints of Kmelia were invisible in the
    documentation. Swagger strips the regular expression of a path template, so
    {path: \d+(/\d+)*/children} was reduced to {path} and collided with the
    three other ones. The literal suffix now sits outside the template, which
    matches the very same URIs;
  * NewsResource caught back the WebApplicationException it had just thrown and
    turned it into a 503, so neither the 404 of an unknown news nor the refusal
    to delete one ever reached the requester. That refusal answers a 403 now,
    instead of a 401 without any challenge;
  * MediaResolution read the settings of the application from its enum
    constants, making the scan fail with an ExceptionInInitializerError. The
    watermark size is read lazily now;
  * five classes of Quickinfo were missing the licence header.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>f2fe8d93d99b4eb77e672c047d22ce154ba94673</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</file></path><path><editType>add</editType><file>components-restapi/pom.xml</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</file></path><path><editType>add</editType><file>components-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>59908ef73f929070700744af9c79e30cf0066fff</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire, those excluded by @XmlTransient or by an access set
to XmlAccessType.FIELD, and missing the fields that do reach it.

Same resolver as the one of Core, of which this project has its own copy, for
the very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>59908ef73f929070700744af9c79e30cf0066fff</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to
fill that section in, hence the document of its own declared here: the scan
completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published.

Same setting as the one of Core, of which this project has its own copy, for the
very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>add</editType><file>components-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>01111927bc2afba8b8a88f23247f97c2e70eab18</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, its
filter and its schema resolver, the fourteen WAR whose classes are unpacked, and
the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>01111927bc2afba8b8a88f23247f97c2e70eab18</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>021fe614496d0adf069aaade785f13438a7998ca</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were copied here from Silverpeas Core,
where they now sit in a package of their own, org.silverpeas.core.rs.doc,
alongside the annotations documenting the common errors. The copies are dropped
and the parent POM declares the classes of core-rs instead.

The annotations documenting the common errors follow them: the endpoints of the
applications refer them at their new place.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>021fe614496d0adf069aaade785f13438a7998ca</id><msg>Take from core-rs what generates the documentation of the REST API</msg><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>9d3490bf7cd64723cdac38d15472d03679bb8950</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:34 +0200</date><id>9d3490bf7cd64723cdac38d15472d03679bb8950</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)
</comment><date>2026-09-28 14:43:22 +0200</date><id>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)
</comment><date>2026-09-28 14:43:22 +0200</date><id>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>03b14dd2f030f634a99944c3272b31500811242f</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)
</comment><date>2026-09-28 14:43:22 +0200</date><id>03b14dd2f030f634a99944c3272b31500811242f</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>0b6076009ffb133c105e4861267e1cda62176d78</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.

(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>0b6076009ffb133c105e4861267e1cda62176d78</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.

(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><commitId>f371b6452d9360af47926ebccceba45e05d252ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)
</comment><date>2026-09-28 14:43:22 +0200</date><id>f371b6452d9360af47926ebccceba45e05d252ca</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><commitId>bb7f36a57f96d33b8bd92d826056770e3c14e04c</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)
</comment><date>2026-09-28 14:43:22 +0200</date><id>bb7f36a57f96d33b8bd92d826056770e3c14e04c</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>eca5145d6d01f77adce83ef714742073585675ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:43:22 +0200</date><id>eca5145d6d01f77adce83ef714742073585675ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></previousBuild></workflowRun>