<workflowJob _class='org.jenkinsci.plugins.workflow.job.WorkflowJob'><action></action><action></action><action></action><action></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.JobDisplayAction'><displayUrl>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/</displayUrl></action><action _class='com.cloudbees.plugins.credentials.ViewCredentialsAction'><stores></stores></action><description>&lt;p&gt;Job to construct a build version of the complete Silverpeas Collaborative platform.&lt;/p&gt;
&lt;p&gt;This job makes a Silverpeas distribution of a given build version and then publishes into our file repository ready to be downloaded and installed.&lt;/p&gt;
&lt;p&gt;The job is triggered every sunday and wednesday in the night.&lt;/p&gt;</description><displayName>Silverpeas_Master_AutoDeploy</displayName><fullDisplayName>Silverpeas_Master_AutoDeploy</fullDisplayName><fullName>Silverpeas_Master_AutoDeploy</fullName><name>Silverpeas_Master_AutoDeploy</name><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/</url><buildable>true</buildable><build _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0l2pebQNaPUmG7crv</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0uxyCkj6CGoBn7yyg</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260930</displayName><duration>24065087</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260930</fullDisplayName><id>1164</id><keepLog>false</keepLog><number>1164</number><queueId>63961</queueId><result>SUCCESS</result><timestamp>1790789040596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/site/resources/index.html</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>ec9caee6b1242b8d5893ed5ece0884304d811cb0</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

Smart-Doc parses the sources with QDox and chokes on constructs Silverpeas
relies on, silently reporting a success while producing an incomplete
documentation. Swagger scans the compiled classes by reflection and understands
the JAX-RS annotations, so the whole REST API is covered.

The new core-restapi module gathers the web resources of all the modules into a
single OpenAPI 3.1 document, rendered by Redoc and published on its own at
docs/restapi/core. It produces nothing but that documentation and builds only
with the restapi profile, from which the Smart-Doc plugin is dropped.

All the 217 operations, spread over 168 paths and 86 schemas, are now
documented: a summary, a success response with its schema, and the errors the
endpoint can answer. The responses common to several endpoints are declared once
for all:

  * @Authenticated and @Authorized, besides the security schemes they already
    described, bring the 401 and 403 responses of the protected resources;
  * the 503 is brought by CommonResponsesFilter, applied once the specification
    has been figured out. It cannot come from another meta-annotation of the web
    resources: at class level Swagger returns the responses of the first
    meta-annotation declaring some instead of merging them all, so a second one
    would silently discard the responses of @Authenticated and @Authorized;
  * the recurring 404, 400 and 409 are factored out into the @NotFound,
    @BadRequest and @Conflict annotations of the new annotation.doc package.
    Contrary to the class level one, the method level lookup of Swagger does
    merge, but the description of such an annotation takes precedence over the
    one an endpoint would declare for the same status code, hence an endpoint
    needing another wording must not be annotated.

Documenting the endpoints brought several defects to light, which are fixed
here: the wrong descriptions of the personal space endpoints of SpaceResource, a
test endpoint left over in CipherKeyResource, and the conflicting setters of
AbstractI18NBean for the translations property, which made the scan fail.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>ec9caee6b1242b8d5893ed5ece0884304d811cb0</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</file></path><path><editType>add</editType><file>core-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</file></path><path><editType>add</editType><file>core-restapi/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><commitId>c097c5d943af83fb5ce284ad45b733a9d806b761</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire and missing others that do:

  * an entity whose access is set to XmlAccessType.FIELD was described by its
    getters instead of its fields. SpaceAppearanceEntity came out with two
    properties where six are serialized;
  * a member annotated with @XmlTransient was described all the same.
    PdcAxisValueEntity came out with eleven properties where nine are
    serialized.

The JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,
@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of
a schema, never its visibility. As for the Jackson module bringing that
introspector, it does declare itself to the ServiceLoader, but Swagger never
asks for the modules available in the classpath.

The resolver declared here sets the introspector on a mapper of its own, the
very way the JSON codec of Silverpeas does, so that it applies to the resolution
of the schemas only. Ten business objects were documented that no endpoint ever
answers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the
like -- and they are gone now.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>c097c5d943af83fb5ce284ad45b733a9d806b761</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</affectedPath><commitId>692a545a5347eefc22d5e8f1949b6ce94151f274</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no
parameter to fill that section in, hence the document of its own declared here:
the scan completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published. The published tree is now made of the rendering page, the
specification in both of its formats, and the rendering engine.

Skipping the site altogether looked simpler but isn't an option: the deploy goal
of the site plugin reads the very same maven.site.skip property as its site
goal, so the documentation would have silently stopped being published.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>692a545a5347eefc22d5e8f1949b6ce94151f274</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>078323a23b15cb23bbbcaa797991a709645d0f7d</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, the
routes of the SCIM API not to publish, its filter and its schema resolver, the
WAR whose classes are unpacked, and the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>078323a23b15cb23bbbcaa797991a709645d0f7d</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><commitId>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Gather in core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were duplicated, one copy per project
documenting its REST API, the two being identical but for their package. They
are gathered here, beside the annotations documenting the common errors, in a
package of their own: org.silverpeas.core.rs.doc.

Their name being the same for every project now, the parent POM declares them
once for all, and nothing is left to keep the copies in step.

The counterpart is that core-rs, a module of production, depends on swagger-core
to compile them. The dependency is provided, so nothing of it is shipped, and
neither the filter nor the resolver plays any role at runtime: both are read
when generating the documentation only.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</id><msg>Gather in core-rs what generates the documentation of the REST API</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:17 +0200</date><id>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>5f5891af886c501d82d72d54f15552e3775e0ce7</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)
</comment><date>2026-09-28 14:42:28 +0200</date><id>5f5891af886c501d82d72d54f15552e3775e0ce7</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>018ed026afbb76a9ad52281cd62b8e284b9a914a</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)
</comment><date>2026-09-28 14:42:28 +0200</date><id>018ed026afbb76a9ad52281cd62b8e284b9a914a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</affectedPath><commitId>37283d39cead2166ad9483d373658c2b8e414c95</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)
</comment><date>2026-09-28 14:42:28 +0200</date><id>37283d39cead2166ad9483d373658c2b8e414c95</id><msg>Fix vulnerability #1459</msg><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>b2900e3c4738e94ab34622ee8a48197f7921a09f</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)
</comment><date>2026-09-28 14:42:28 +0200</date><id>b2900e3c4738e94ab34622ee8a48197f7921a09f</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>23acd94a451f35afaf18324777b344292593341b</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.

(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)
</comment><date>2026-09-28 14:42:28 +0200</date><id>23acd94a451f35afaf18324777b344292593341b</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>52843258f403c47fb8a0b51a75295f883fb98eda</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)
</comment><date>2026-09-28 14:42:28 +0200</date><id>52843258f403c47fb8a0b51a75295f883fb98eda</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>df92a06600aedb5b24bad01559165e839421c2b5</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:42:28 +0200</date><id>df92a06600aedb5b24bad01559165e839421c2b5</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>db15a2e30508fb101a2addaf4780cc6479eb9270</commitId><timestamp>1790599436000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:43:56 +0200</date><id>db15a2e30508fb101a2addaf4780cc6479eb9270</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>3f5875d5832af01276050f9ad75a08f7ddb4dd30</commitId><timestamp>1790608429000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:13:49 +0200</date><id>3f5875d5832af01276050f9ad75a08f7ddb4dd30</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>components-restapi/src/site/resources/index.html</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>f2fe8d93d99b4eb77e672c047d22ce154ba94673</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

The new components-restapi module gathers the web resources of the fourteen
applications into a single OpenAPI 3.1 document, rendered by Redoc and published
on its own at docs/restapi/components. It produces nothing but that
documentation and builds only with the restapi profile, from which the Smart-Doc
plugin is dropped.

All the 81 operations, spread over 70 paths and 81 schemas, are now documented.
The twenty-two operations of the almanach are inherited from the calendar
resources of Core and needed nothing: Swagger reads the annotations of the
overridden methods. The others got a summary, a success response with its
schema, and the errors they can answer, the recurring ones coming from the
@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is
brought by CommonResponsesFilter, of which this project has its own copy.

Documenting the endpoints brought several defects to light, which are fixed
here:

  * three of the four folder endpoints of Kmelia were invisible in the
    documentation. Swagger strips the regular expression of a path template, so
    {path: \d+(/\d+)*/children} was reduced to {path} and collided with the
    three other ones. The literal suffix now sits outside the template, which
    matches the very same URIs;
  * NewsResource caught back the WebApplicationException it had just thrown and
    turned it into a 503, so neither the 404 of an unknown news nor the refusal
    to delete one ever reached the requester. That refusal answers a 403 now,
    instead of a 401 without any challenge;
  * MediaResolution read the settings of the application from its enum
    constants, making the scan fail with an ExceptionInInitializerError. The
    watermark size is read lazily now;
  * five classes of Quickinfo were missing the licence header.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>f2fe8d93d99b4eb77e672c047d22ce154ba94673</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</file></path><path><editType>add</editType><file>components-restapi/pom.xml</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</file></path><path><editType>add</editType><file>components-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>59908ef73f929070700744af9c79e30cf0066fff</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire, those excluded by @XmlTransient or by an access set
to XmlAccessType.FIELD, and missing the fields that do reach it.

Same resolver as the one of Core, of which this project has its own copy, for
the very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>59908ef73f929070700744af9c79e30cf0066fff</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to
fill that section in, hence the document of its own declared here: the scan
completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published.

Same setting as the one of Core, of which this project has its own copy, for the
very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>add</editType><file>components-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>01111927bc2afba8b8a88f23247f97c2e70eab18</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, its
filter and its schema resolver, the fourteen WAR whose classes are unpacked, and
the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>01111927bc2afba8b8a88f23247f97c2e70eab18</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>021fe614496d0adf069aaade785f13438a7998ca</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were copied here from Silverpeas Core,
where they now sit in a package of their own, org.silverpeas.core.rs.doc,
alongside the annotations documenting the common errors. The copies are dropped
and the parent POM declares the classes of core-rs instead.

The annotations documenting the common errors follow them: the endpoints of the
applications refer them at their new place.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>021fe614496d0adf069aaade785f13438a7998ca</id><msg>Take from core-rs what generates the documentation of the REST API</msg><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>9d3490bf7cd64723cdac38d15472d03679bb8950</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:34 +0200</date><id>9d3490bf7cd64723cdac38d15472d03679bb8950</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)
</comment><date>2026-09-28 14:43:22 +0200</date><id>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)
</comment><date>2026-09-28 14:43:22 +0200</date><id>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>03b14dd2f030f634a99944c3272b31500811242f</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)
</comment><date>2026-09-28 14:43:22 +0200</date><id>03b14dd2f030f634a99944c3272b31500811242f</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>0b6076009ffb133c105e4861267e1cda62176d78</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.

(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>0b6076009ffb133c105e4861267e1cda62176d78</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.

(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><commitId>f371b6452d9360af47926ebccceba45e05d252ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)
</comment><date>2026-09-28 14:43:22 +0200</date><id>f371b6452d9360af47926ebccceba45e05d252ca</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><commitId>bb7f36a57f96d33b8bd92d826056770e3c14e04c</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)
</comment><date>2026-09-28 14:43:22 +0200</date><id>bb7f36a57f96d33b8bd92d826056770e3c14e04c</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>eca5145d6d01f77adce83ef714742073585675ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:43:22 +0200</date><id>eca5145d6d01f77adce83ef714742073585675ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></previousBuild></build><build _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='hudson.model.CauseAction'><cause _class='hudson.model.Cause$UserIdCause'><shortDescription>Démarré par l'utilisateur Miguel Moquillon</shortDescription><userId>mmoquillon</userId><userName>Miguel Moquillon</userName></cause></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1163</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaDn1HDHG2nnBI00r1HL</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'><url>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</url></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260928</displayName><duration>7569546</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260928</fullDisplayName><id>1163</id><keepLog>false</keepLog><number>1163</number><queueId>63338</queueId><result>SUCCESS</result><timestamp>1790589603324</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><nextBuild><number>1164</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url></nextBuild><previousBuild><number>1162</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1162/</url></previousBuild></build><build _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='hudson.model.CauseAction'><cause _class='hudson.model.Cause$UserIdCause'><shortDescription>Démarré par l'utilisateur Miguel Moquillon</shortDescription><userId>mmoquillon</userId><userName>Miguel Moquillon</userName></cause></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><building>false</building><displayName>#1162</displayName><duration>3135500</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy #1162</fullDisplayName><id>1162</id><keepLog>false</keepLog><number>1162</number><queueId>63310</queueId><result>FAILURE</result><timestamp>1790584035065</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1162/</url><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><nextBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></nextBuild><previousBuild><number>1161</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1161/</url></previousBuild></build><build _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1161</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaDkQZI5tD7Bd_4xbMm1</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'><url>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</url></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><building>false</building><displayName>#1161</displayName><duration>6150032</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy #1161</fullDisplayName><id>1161</id><keepLog>false</keepLog><number>1161</number><queueId>63261</queueId><result>FAILURE</result><timestamp>1790529840597</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1161/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-editorSignature.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/tr/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ml/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ff/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/zh-TW/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ro/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/fi/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ur/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/nl/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/son/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/cak/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/brx/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/wo/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/messageBar_closingButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sr/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/tl/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/el/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/en-GB/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/si/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/mr/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ltg/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/lo/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_PDFJS_QCMS</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/lij/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/gl/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-viewsManagerToggle.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/jbig2_nowasm_fallback.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ko/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ru/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/af/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/editor-toolbar-edit.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/scn/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/fr/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/cy/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ckb/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-sidebarToggle.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/altText_disclaimer.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/br/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/pages_selected.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/cursor-editorFreeHighlight.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/my/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/bs/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sco/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/messageBar_info.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/comment-closeButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/comment-popup-editButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/zh-CN/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/trs/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/hr/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/openjpeg.wasm</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_JBIG2</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/comment-actionsButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/cs/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/altText_spinner.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/uk/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sv-SE/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/sp-viewer.css</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/openjpeg_nowasm_fallback.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/es-AR/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sat/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/th/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/core/pdf.sandbox.min.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/mk/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/viewer.jsp</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/fy-NL/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ar/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/skr/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/kk/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/xh/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/core/pdf.worker.min.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/nb-NO/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_QCMS</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/kn/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/fur/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ga-IE/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ca/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/vi/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/rm/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/iccs/CGATS001Compat-v2-micro.icc</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/bo/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/da/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/szl/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/qcms_bg.wasm</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/comment-editButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/km/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sl/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/es-ES/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/core/pdf.min.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/altText_warning.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/eo/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/kab/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/gn/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sk/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-editorStamp.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/uz/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/hi-IN/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/pl/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/pt-BR/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ta/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/et/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ast/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ne-NP/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ach/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/meh/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/bn/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/an/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/hsb/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/az/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/it/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_PDFJS_OPENJPEG</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-editorFreeText.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-signaturePropertiesError.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/standard_fonts/LICENSE_LIBERATION</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/gu-IN/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/id/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/viewer.min.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-menuArrowNova.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/dsb/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/hye/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/fa/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/gd/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/nn-NO/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/be/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/gv-toolbarButton-openinapp.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ia/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ja/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ka/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/quickjs-eval.js</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/tg/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/messageBar_warning.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/viewer.min.css</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/pt-PT/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/en-US/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_PDFJS_JBIG2</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/pages_viewArrow.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/pages_closeButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/ms/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/is/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/en-CA/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/lv/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/es-CL/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/hy-AM/viewer.ftl</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/util/viewgenerator/html/JavascriptPluginInclusion.java</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/pa-IN/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/bqi/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/pages_viewButton.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/de/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/he/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/te/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/cursor-editorTextHighlight.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/iccs/LICENSE</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/locale.json</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sq/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/hu/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/oc/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/checkmark.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/sc/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/eu/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/signature-properties-row-check.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/doc/README.md</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/jbig2.wasm</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/bg/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/lt/viewer.ftl</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/quickjs-eval.wasm</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-signaturePropertiesVerified.svg</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_OPENJPEG</affectedPath><affectedPath>core-war/src/main/webapp/media/jsp/pdf/locale/es-MX/viewer.ftl</affectedPath><commitId>c26f88f64443a7723b9bcd9aa671e8745b38876e</commitId><timestamp>1790255803000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Update the embedded PDF viewer to PDF.js 6.3.289

The viewer was still running PDF.js 4.0.379. Beyond the sources themselves, the
upgrade requires the two manual modifications of viewer.min.js described in
doc/README.md to be applied again: the wiring of
window.SP_PDF_VIEWER_L10N_TEXT_MODIFIER into GenericL10n#createBundle, and the
completion of the webviewerloaded event detail in webViewerLoad, upstream
publishing only the source window there. Without the latter,
e.detail.viewerAppOptions is undefined and none of the Silverpeas settings is
applied, leaving the viewer with its default worker source.

The markup of the toolbars has been reworked upstream, so the body of viewer.jsp
is taken again from viewer.html: the left sidebar is replaced by the views
manager nested into the toolbar, most of the buttons are renamed with a Button
suffix, their former identifier being now the one of the wrapping
div.toolbarButtonWithContainer, and the alert, undo bar and signature dialogs are
new. The obsolete selectors of sp-viewer.css are updated accordingly.

PDF.js now decodes the JBIG2, OpenJPEG and QCMS streams and runs the PDF
scripting through WebAssembly, and reads the ICC profiles from its own resource
folder. Both folders are given to the viewer through new PdfViewerSettings
entries and applied as the wasmUrl and iccUrl options, along with
standardFontDataUrl which was never set: relative to viewer.jsp, their default
value resolves outside the plugin and fails to be fetched. The locale option is
replaced by localeProperties, and the edition tools are hidden by the
annotationEditorMode option rather than by removing each button, the viewer
taking care of its whole tool group by itself.

All the viewers of a page register their listener on the parent document, so
each one was also handling the events dispatched by the others: the first
replaced the presentation mode button by its clone, and every later pass worked
on a node already detached from the document, failing on a null parent. The
listener now handles only the event whose source is its own window.
</comment><date>2026-09-24 15:16:43 +0200</date><id>c26f88f64443a7723b9bcd9aa671e8745b38876e</id><msg>Update the embedded PDF viewer to PDF.js 6.3.289</msg><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/kab/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ar/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/be/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_JBIG2</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/nb-NO/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/viewer.min.css</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/openjpeg_nowasm_fallback.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/gn/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/oc/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/core/pdf.sandbox.min.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/en-CA/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/si/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/eo/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/pages_closeButton.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/br/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/brx/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/wo/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ca/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/gu-IN/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/id/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/rm/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/mr/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/comment-popup-editButton.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/pt-PT/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/quickjs-eval.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ia/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-signaturePropertiesError.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/viewer.jsp</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ja/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/meh/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/qcms_bg.wasm</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/core/pdf.min.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/zh-CN/viewer.ftl</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/util/viewgenerator/html/JavascriptPluginInclusion.java</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/messageBar_warning.svg</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/pages_viewArrow.svg</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-viewsManagerToggle.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sv-SE/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/sp-viewer.css</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/locale.json</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/da/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/eu/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/hy-AM/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/nn-NO/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/de/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/vi/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/gd/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/th/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/skr/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/messageBar_info.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/my/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/trs/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/iccs/CGATS001Compat-v2-micro.icc</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/jbig2_nowasm_fallback.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ms/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/checkmark.svg</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/quickjs-eval.wasm</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/es-AR/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/comment-actionsButton.svg</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-menuArrowNova.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ltg/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/hr/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/hu/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ko/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/uk/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/comment-editButton.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/kn/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/bg/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/el/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/tr/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/lv/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/hi-IN/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/jbig2.wasm</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/cs/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ta/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/km/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/an/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/bn/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/cak/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ml/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/altText_warning.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sco/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/xh/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/es-MX/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/mk/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sk/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-editorSignature.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-editorStamp.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/kk/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/et/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/iccs/LICENSE</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/is/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_PDFJS_JBIG2</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/lt/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ach/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/he/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/dsb/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/bs/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/lij/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/pt-BR/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/it/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/bo/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/fur/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_QCMS</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/cursor-editorFreeHighlight.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/es-CL/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_OPENJPEG</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sr/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/viewer.min.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sl/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/messageBar_closingButton.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/az/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ne-NP/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_PDFJS_OPENJPEG</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/en-US/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/editor-toolbar-edit.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ur/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/gl/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/fr/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ro/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-signaturePropertiesVerified.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/fa/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ff/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sq/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/altText_disclaimer.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/es-ES/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/hye/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/comment-closeButton.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/zh-TW/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/te/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/altText_spinner.svg</file></path><path><editType>delete</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-sidebarToggle.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/tl/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/cy/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/szl/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/bqi/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/pages_selected.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/nl/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/lo/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/core/pdf.worker.min.js</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/fi/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/signature-properties-row-check.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ast/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/toolbarButton-editorFreeText.svg</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/LICENSE_PDFJS_QCMS</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/scn/viewer.ftl</file></path><path><editType>delete</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/gv-toolbarButton-openinapp.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/standard_fonts/LICENSE_LIBERATION</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/doc/README.md</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/wasm/openjpeg.wasm</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ga-IE/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ckb/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/fy-NL/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/pa-IN/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/uz/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/pl/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/af/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ru/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sat/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/en-GB/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/sc/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/tg/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/pages_viewButton.svg</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/son/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/hsb/viewer.ftl</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/media/jsp/pdf/locale/ka/viewer.ftl</file></path><path><editType>add</editType><file>core-war/src/main/webapp/media/jsp/pdf/images/cursor-editorTextHighlight.svg</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><commitId>16f409d825312915c2a820091b3da9709e104277</commitId><timestamp>1790255899000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Stop the embedded PDF viewer from failing on the byte ranges it requests

Displaying a publication holding several attached documents ends frequently, on
one of the viewers and never the same one, in

  Message: Invalid PDF structure.

The content of a pdf is guarded by a token set in cache by the viewer page and
consumed by EmbedMediaViewerResource#getPdfContent, which answers otherwise a
redirection to the viewer page. PDF.js doesn't fetch the document in a single
request: once the first one answered, it asks again on the same URL for the byte
ranges it needs, typically to reach the cross-reference table. That second
request finds no token anymore and receives the HTML of the viewer page in place
of the bytes of the document, which it reports as an invalid structure. Whether
the document is displayed depends on the full stream having been received before
the range answer was needed, hence the randomness. The time to live of ten
seconds adds a second way to fail when several viewers compete for the
connections of the browser.

The token is no longer consumed on the first reading and carries a time to idle
instead of a time to live, PerElementExpiration renewing it at each access: the
access stays valid as long as the viewer actually uses it and expires a minute
after the last one. The authorization itself is unchanged, getPdfContent still
resolving the document through getAuthorizedResourceView.
</comment><date>2026-09-24 15:18:19 +0200</date><id>16f409d825312915c2a820091b3da9709e104277</id><msg>Stop the embedded PDF viewer from failing on the byte ranges it requests</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-identitycard.js</affectedPath><commitId>a66c5a517e740105ad5aa1f92aa5c99561543e7b</commitId><timestamp>1790256861000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>User data to render in an identity card can be other than a string.

For its rendering any user data is unescaped for HTML. But this is a
string function and some user data can be not a string. So, test before
applying the `unescapeHTML()` function the user data is well a string.
Otherwise don't apply the function.
</comment><date>2026-09-24 15:34:21 +0200</date><id>a66c5a517e740105ad5aa1f92aa5c99561543e7b</id><msg>User data to render in an identity card can be other than a string.</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-identitycard.js</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-layout.js</affectedPath><commitId>539a33537894703e6f9a66b649be686dc8712e45</commitId><timestamp>1790258735000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Log the close code of the SSE WebSockets and count each failed connection once

A WebSocket that fails fires an error event, carrying no information at all,
always followed by a close event. Both of them called the error handler of
SilverpeasEventSource, so each failed connection was counted twice in the
reconnection attempts and logged as a meaningless error ({"isTrusted":true}).
The close event is now the only one in charge of the reconnection, and it logs
the close code and reason, which are the only hints about the failure (1006
for an abnormal closure, as when a reverse proxy doesn't forward the Upgrade
headers of the handshake).

Co-Authored-By: Claude Opus 5.5 (1M context) &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-24 16:05:35 +0200</date><id>539a33537894703e6f9a66b649be686dc8712e45</id><msg>Log the close code of the SSE WebSockets and count each failed connection once</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-layout.js</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-ddUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadData.java</affectedPath><commitId>9b57c3fe0a2b3d7ef1303c4e35142388f6a9dc0a</commitId><timestamp>1790265833000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug #15479: the file name in the X-FULL-PATH header is again URI-encoded

HTTP headers can carry only ISO-8859-1 characters. Since the fix of bug #15388,
the name of a dropped file was sent raw in the X-FULL-PATH header. On Mac OS,
file names are in NFD form, so an accented character is followed by a combining
diacritic that isn't a Latin-1 character: XMLHttpRequest#setRequestHeader()
then throws an error and the file is never uploaded.

The name is now URI-encoded by the client (drag &amp; drop and file upload
components) and decoded by FileUploadData before being normalized to NFC.
To keep the protection brought by the fix of vulnerability #15358, the
MassiveWebSecurityFilter checks also the URI-decoded value of the custom
X-* headers against XSS and SQL injections.

Co-Authored-By: Claude Fable 5.1 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-24 18:03:53 +0200</date><id>9b57c3fe0a2b3d7ef1303c4e35142388f6a9dc0a</id><msg>Fix bug #15479: the file name in the X-FULL-PATH header is again URI-encoded</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadData.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-ddUpload.js</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentEntity.java</affectedPath><affectedPath>core-api/src/test/java/org/silverpeas/core/util/JSONCodecTest.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/JSONCodec.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/ObjectMapperResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><commitId>5cc19e86433a938243d9355b17b64b2842fd5304</commitId><timestamp>1790325476000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug #15462: a comment can again be modified by its author

The comments widget sends back to the server, in a PUT request, the
whole JSON representation of a comment it got from a GET request, with
only the text changed. Since the migration to WildFly 39, such a request
was rejected with a 400 HTTP status: the JSON representation carries the
read-only properties of the comment's author (blockedState, status, ...),
and the Jackson mapper used by RESTEasy 6.2 rejects any property that is
unknown to the entity to deserialize.

Until 6.4, the REST API tolerated those properties without anyone knowing
why: the PSU SCIM library then embedded in the WAR registered for the
whole application a ContextResolver&lt;ObjectMapper&gt; whose mapper ignored
the unknown properties. With the switch to Apache SCIMple, whose JSON
provider is scoped to the SCIM resources only, that resolver went away
and the REST API fell back on the default, strict, mapper of RESTEasy.

So, Silverpeas now provides its own ContextResolver&lt;ObjectMapper&gt; to the
JAX-RS runtime. The mapper it serves is built by the new method
JSONCodec.newObjectMapper(), so that a bean is (un)marshalled the same
way by the REST API and by the JSON codec: Jackson and Jakarta XML
Binding annotations are both taken into account, null properties are
omitted, and unknown properties are ignored. The codec also uses now a
single shared mapper instead of building a new one at each call.

Also fix the URI of the comment returned by the PUT request, which
carried the comment identifier twice.
</comment><date>2026-09-25 10:37:56 +0200</date><id>5cc19e86433a938243d9355b17b64b2842fd5304</id><msg>Fix bug #15462: a comment can again be modified by its author</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/ObjectMapperResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentEntity.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/JSONCodec.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>add</editType><file>core-api/src/test/java/org/silverpeas/core/util/JSONCodecTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/java/org/silverpeas/web/socialnetwork/newsfeed/servlets/NewsFeedJSONServlet.java</affectedPath><commitId>1304c37395ed48d15f3de5dd28778f74216c84a5</commitId><timestamp>1790340800000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix the display of the accepted-invitation event in the news feed

The label of a RELATIONSHIP social information embeds the HTML fragment
generated by UserNameGenerator so that the name of the new contact is
zoomable. This fragment was passed to LocalizationBundle#getStringWithParams
which HTML-encodes all its string parameters, so the fragment was encoded a
second time and the &lt;span&gt; tags were displayed as text in the feed.

The message is now formatted directly with MessageFormat from the raw bundle
pattern. Only the full name of the contact remains HTML-encoded, which is
already done by UserNameGenerator.
</comment><date>2026-09-25 14:53:20 +0200</date><id>1304c37395ed48d15f3de5dd28778f74216c84a5</id><msg>Fix the display of the accepted-invitation event in the news feed</msg><path><editType>edit</editType><file>core-war/src/main/java/org/silverpeas/web/socialnetwork/newsfeed/servlets/NewsFeedJSONServlet.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><commitId>40c8b4dd7931335c08801b762a355283f03d4ffa</commitId><timestamp>1790349587000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>The password checking web service rejects a request without password

Since the fix of bug #15462, the Jackson mapper of the REST API ignores
the JSON properties unknown to the web entity to deserialize. A POST
request at password/policy/checking whose body carries no "value"
property is thus no longer rejected at deserialization: it yields a
PasswordEntity with a null password, which the PasswordRulesService
checked without complaint. The integration test
PasswordPolicyCheckingIT#postAnInvalidResourceState, which expects a 400
HTTP status for such a body, then failed with a 200.

Like the other resources handling POST requests, PasswordResource now
validates the entity it receives and answers with a 400 HTTP status when
it carries no password to check.
</comment><date>2026-09-25 17:19:47 +0200</date><id>40c8b4dd7931335c08801b762a355283f03d4ffa</id><msg>The password checking web service rejects a request without password</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/java/org/silverpeas/web/jobdomain/control/JobDomainPeasSessionController.java</affectedPath><commitId>969e2118e87aad06e5a036b5cec76d30c7e30867</commitId><timestamp>1790350669000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Remove leftover debug code that removed 60 users instead of one

Commit 2d747ab27b (fix of bug #15217) left in
JobDomainPeasSessionController#removeUser a debugging loop that removed
the users whose identifiers range from the given one to the given one
plus 60, without any failure control. Restore the original behaviour:
only the requested user is removed, and a failure raises an exception.

Co-Authored-By: Claude Fable 5.1 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-25 17:37:49 +0200</date><id>969e2118e87aad06e5a036b5cec76d30c7e30867</id><msg>Remove leftover debug code that removed 60 users instead of one</msg><path><editType>edit</editType><file>core-war/src/main/java/org/silverpeas/web/jobdomain/control/JobDomainPeasSessionController.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><nextBuild><number>1162</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1162/</url></nextBuild><previousBuild><number>1160</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1160/</url></previousBuild></build><build _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><branch><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><branch><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><branch><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260921</displayName><duration>17691</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260921</fullDisplayName><id>1160</id><keepLog>false</keepLog><number>1160</number><queueId>62135</queueId><result>SUCCESS</result><timestamp>1790184240597</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1160/</url><inProgress>false</inProgress><nextBuild><number>1161</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1161/</url></nextBuild></build><color>blue</color><firstBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><branch><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><branch><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><branch><SHA1>3a57787faaff0b7941c04146ff51cccd1b963cfc</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1160</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260921</displayName><duration>17691</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260921</fullDisplayName><id>1160</id><keepLog>false</keepLog><number>1160</number><queueId>62135</queueId><result>SUCCESS</result><timestamp>1790184240597</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1160/</url><inProgress>false</inProgress><nextBuild><number>1161</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1161/</url></nextBuild></firstBuild><healthReport><description>Stabilité du build : 2 des 5 derniers builds ont échoué.</description><iconClassName>icon-health-40to59</iconClassName><iconUrl>health-40to59.png</iconUrl><score>60</score></healthReport><keepDependencies>false</keepDependencies><lastBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0l2pebQNaPUmG7crv</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0uxyCkj6CGoBn7yyg</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260930</displayName><duration>24065087</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260930</fullDisplayName><id>1164</id><keepLog>false</keepLog><number>1164</number><queueId>63961</queueId><result>SUCCESS</result><timestamp>1790789040596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/site/resources/index.html</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>ec9caee6b1242b8d5893ed5ece0884304d811cb0</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

Smart-Doc parses the sources with QDox and chokes on constructs Silverpeas
relies on, silently reporting a success while producing an incomplete
documentation. Swagger scans the compiled classes by reflection and understands
the JAX-RS annotations, so the whole REST API is covered.

The new core-restapi module gathers the web resources of all the modules into a
single OpenAPI 3.1 document, rendered by Redoc and published on its own at
docs/restapi/core. It produces nothing but that documentation and builds only
with the restapi profile, from which the Smart-Doc plugin is dropped.

All the 217 operations, spread over 168 paths and 86 schemas, are now
documented: a summary, a success response with its schema, and the errors the
endpoint can answer. The responses common to several endpoints are declared once
for all:

  * @Authenticated and @Authorized, besides the security schemes they already
    described, bring the 401 and 403 responses of the protected resources;
  * the 503 is brought by CommonResponsesFilter, applied once the specification
    has been figured out. It cannot come from another meta-annotation of the web
    resources: at class level Swagger returns the responses of the first
    meta-annotation declaring some instead of merging them all, so a second one
    would silently discard the responses of @Authenticated and @Authorized;
  * the recurring 404, 400 and 409 are factored out into the @NotFound,
    @BadRequest and @Conflict annotations of the new annotation.doc package.
    Contrary to the class level one, the method level lookup of Swagger does
    merge, but the description of such an annotation takes precedence over the
    one an endpoint would declare for the same status code, hence an endpoint
    needing another wording must not be annotated.

Documenting the endpoints brought several defects to light, which are fixed
here: the wrong descriptions of the personal space endpoints of SpaceResource, a
test endpoint left over in CipherKeyResource, and the conflicting setters of
AbstractI18NBean for the translations property, which made the scan fail.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>ec9caee6b1242b8d5893ed5ece0884304d811cb0</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</file></path><path><editType>add</editType><file>core-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</file></path><path><editType>add</editType><file>core-restapi/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><commitId>c097c5d943af83fb5ce284ad45b733a9d806b761</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire and missing others that do:

  * an entity whose access is set to XmlAccessType.FIELD was described by its
    getters instead of its fields. SpaceAppearanceEntity came out with two
    properties where six are serialized;
  * a member annotated with @XmlTransient was described all the same.
    PdcAxisValueEntity came out with eleven properties where nine are
    serialized.

The JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,
@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of
a schema, never its visibility. As for the Jackson module bringing that
introspector, it does declare itself to the ServiceLoader, but Swagger never
asks for the modules available in the classpath.

The resolver declared here sets the introspector on a mapper of its own, the
very way the JSON codec of Silverpeas does, so that it applies to the resolution
of the schemas only. Ten business objects were documented that no endpoint ever
answers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the
like -- and they are gone now.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>c097c5d943af83fb5ce284ad45b733a9d806b761</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</affectedPath><commitId>692a545a5347eefc22d5e8f1949b6ce94151f274</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no
parameter to fill that section in, hence the document of its own declared here:
the scan completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published. The published tree is now made of the rendering page, the
specification in both of its formats, and the rendering engine.

Skipping the site altogether looked simpler but isn't an option: the deploy goal
of the site plugin reads the very same maven.site.skip property as its site
goal, so the documentation would have silently stopped being published.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>692a545a5347eefc22d5e8f1949b6ce94151f274</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>078323a23b15cb23bbbcaa797991a709645d0f7d</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, the
routes of the SCIM API not to publish, its filter and its schema resolver, the
WAR whose classes are unpacked, and the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>078323a23b15cb23bbbcaa797991a709645d0f7d</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><commitId>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Gather in core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were duplicated, one copy per project
documenting its REST API, the two being identical but for their package. They
are gathered here, beside the annotations documenting the common errors, in a
package of their own: org.silverpeas.core.rs.doc.

Their name being the same for every project now, the parent POM declares them
once for all, and nothing is left to keep the copies in step.

The counterpart is that core-rs, a module of production, depends on swagger-core
to compile them. The dependency is provided, so nothing of it is shipped, and
neither the filter nor the resolver plays any role at runtime: both are read
when generating the documentation only.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</id><msg>Gather in core-rs what generates the documentation of the REST API</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:17 +0200</date><id>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>5f5891af886c501d82d72d54f15552e3775e0ce7</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)
</comment><date>2026-09-28 14:42:28 +0200</date><id>5f5891af886c501d82d72d54f15552e3775e0ce7</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>018ed026afbb76a9ad52281cd62b8e284b9a914a</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)
</comment><date>2026-09-28 14:42:28 +0200</date><id>018ed026afbb76a9ad52281cd62b8e284b9a914a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</affectedPath><commitId>37283d39cead2166ad9483d373658c2b8e414c95</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)
</comment><date>2026-09-28 14:42:28 +0200</date><id>37283d39cead2166ad9483d373658c2b8e414c95</id><msg>Fix vulnerability #1459</msg><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>b2900e3c4738e94ab34622ee8a48197f7921a09f</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)
</comment><date>2026-09-28 14:42:28 +0200</date><id>b2900e3c4738e94ab34622ee8a48197f7921a09f</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>23acd94a451f35afaf18324777b344292593341b</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.

(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)
</comment><date>2026-09-28 14:42:28 +0200</date><id>23acd94a451f35afaf18324777b344292593341b</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>52843258f403c47fb8a0b51a75295f883fb98eda</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)
</comment><date>2026-09-28 14:42:28 +0200</date><id>52843258f403c47fb8a0b51a75295f883fb98eda</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>df92a06600aedb5b24bad01559165e839421c2b5</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:42:28 +0200</date><id>df92a06600aedb5b24bad01559165e839421c2b5</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>db15a2e30508fb101a2addaf4780cc6479eb9270</commitId><timestamp>1790599436000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:43:56 +0200</date><id>db15a2e30508fb101a2addaf4780cc6479eb9270</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>3f5875d5832af01276050f9ad75a08f7ddb4dd30</commitId><timestamp>1790608429000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:13:49 +0200</date><id>3f5875d5832af01276050f9ad75a08f7ddb4dd30</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>components-restapi/src/site/resources/index.html</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>f2fe8d93d99b4eb77e672c047d22ce154ba94673</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

The new components-restapi module gathers the web resources of the fourteen
applications into a single OpenAPI 3.1 document, rendered by Redoc and published
on its own at docs/restapi/components. It produces nothing but that
documentation and builds only with the restapi profile, from which the Smart-Doc
plugin is dropped.

All the 81 operations, spread over 70 paths and 81 schemas, are now documented.
The twenty-two operations of the almanach are inherited from the calendar
resources of Core and needed nothing: Swagger reads the annotations of the
overridden methods. The others got a summary, a success response with its
schema, and the errors they can answer, the recurring ones coming from the
@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is
brought by CommonResponsesFilter, of which this project has its own copy.

Documenting the endpoints brought several defects to light, which are fixed
here:

  * three of the four folder endpoints of Kmelia were invisible in the
    documentation. Swagger strips the regular expression of a path template, so
    {path: \d+(/\d+)*/children} was reduced to {path} and collided with the
    three other ones. The literal suffix now sits outside the template, which
    matches the very same URIs;
  * NewsResource caught back the WebApplicationException it had just thrown and
    turned it into a 503, so neither the 404 of an unknown news nor the refusal
    to delete one ever reached the requester. That refusal answers a 403 now,
    instead of a 401 without any challenge;
  * MediaResolution read the settings of the application from its enum
    constants, making the scan fail with an ExceptionInInitializerError. The
    watermark size is read lazily now;
  * five classes of Quickinfo were missing the licence header.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>f2fe8d93d99b4eb77e672c047d22ce154ba94673</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</file></path><path><editType>add</editType><file>components-restapi/pom.xml</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</file></path><path><editType>add</editType><file>components-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>59908ef73f929070700744af9c79e30cf0066fff</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire, those excluded by @XmlTransient or by an access set
to XmlAccessType.FIELD, and missing the fields that do reach it.

Same resolver as the one of Core, of which this project has its own copy, for
the very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>59908ef73f929070700744af9c79e30cf0066fff</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to
fill that section in, hence the document of its own declared here: the scan
completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published.

Same setting as the one of Core, of which this project has its own copy, for the
very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>add</editType><file>components-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>01111927bc2afba8b8a88f23247f97c2e70eab18</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, its
filter and its schema resolver, the fourteen WAR whose classes are unpacked, and
the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>01111927bc2afba8b8a88f23247f97c2e70eab18</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>021fe614496d0adf069aaade785f13438a7998ca</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were copied here from Silverpeas Core,
where they now sit in a package of their own, org.silverpeas.core.rs.doc,
alongside the annotations documenting the common errors. The copies are dropped
and the parent POM declares the classes of core-rs instead.

The annotations documenting the common errors follow them: the endpoints of the
applications refer them at their new place.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>021fe614496d0adf069aaade785f13438a7998ca</id><msg>Take from core-rs what generates the documentation of the REST API</msg><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>9d3490bf7cd64723cdac38d15472d03679bb8950</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:34 +0200</date><id>9d3490bf7cd64723cdac38d15472d03679bb8950</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)
</comment><date>2026-09-28 14:43:22 +0200</date><id>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)
</comment><date>2026-09-28 14:43:22 +0200</date><id>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>03b14dd2f030f634a99944c3272b31500811242f</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)
</comment><date>2026-09-28 14:43:22 +0200</date><id>03b14dd2f030f634a99944c3272b31500811242f</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>0b6076009ffb133c105e4861267e1cda62176d78</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.

(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>0b6076009ffb133c105e4861267e1cda62176d78</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.

(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><commitId>f371b6452d9360af47926ebccceba45e05d252ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)
</comment><date>2026-09-28 14:43:22 +0200</date><id>f371b6452d9360af47926ebccceba45e05d252ca</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><commitId>bb7f36a57f96d33b8bd92d826056770e3c14e04c</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)
</comment><date>2026-09-28 14:43:22 +0200</date><id>bb7f36a57f96d33b8bd92d826056770e3c14e04c</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>eca5145d6d01f77adce83ef714742073585675ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:43:22 +0200</date><id>eca5145d6d01f77adce83ef714742073585675ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></previousBuild></lastBuild><lastCompletedBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0l2pebQNaPUmG7crv</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0uxyCkj6CGoBn7yyg</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260930</displayName><duration>24065087</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260930</fullDisplayName><id>1164</id><keepLog>false</keepLog><number>1164</number><queueId>63961</queueId><result>SUCCESS</result><timestamp>1790789040596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/site/resources/index.html</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>ec9caee6b1242b8d5893ed5ece0884304d811cb0</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

Smart-Doc parses the sources with QDox and chokes on constructs Silverpeas
relies on, silently reporting a success while producing an incomplete
documentation. Swagger scans the compiled classes by reflection and understands
the JAX-RS annotations, so the whole REST API is covered.

The new core-restapi module gathers the web resources of all the modules into a
single OpenAPI 3.1 document, rendered by Redoc and published on its own at
docs/restapi/core. It produces nothing but that documentation and builds only
with the restapi profile, from which the Smart-Doc plugin is dropped.

All the 217 operations, spread over 168 paths and 86 schemas, are now
documented: a summary, a success response with its schema, and the errors the
endpoint can answer. The responses common to several endpoints are declared once
for all:

  * @Authenticated and @Authorized, besides the security schemes they already
    described, bring the 401 and 403 responses of the protected resources;
  * the 503 is brought by CommonResponsesFilter, applied once the specification
    has been figured out. It cannot come from another meta-annotation of the web
    resources: at class level Swagger returns the responses of the first
    meta-annotation declaring some instead of merging them all, so a second one
    would silently discard the responses of @Authenticated and @Authorized;
  * the recurring 404, 400 and 409 are factored out into the @NotFound,
    @BadRequest and @Conflict annotations of the new annotation.doc package.
    Contrary to the class level one, the method level lookup of Swagger does
    merge, but the description of such an annotation takes precedence over the
    one an endpoint would declare for the same status code, hence an endpoint
    needing another wording must not be annotated.

Documenting the endpoints brought several defects to light, which are fixed
here: the wrong descriptions of the personal space endpoints of SpaceResource, a
test endpoint left over in CipherKeyResource, and the conflicting setters of
AbstractI18NBean for the translations property, which made the scan fail.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>ec9caee6b1242b8d5893ed5ece0884304d811cb0</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</file></path><path><editType>add</editType><file>core-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</file></path><path><editType>add</editType><file>core-restapi/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><commitId>c097c5d943af83fb5ce284ad45b733a9d806b761</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire and missing others that do:

  * an entity whose access is set to XmlAccessType.FIELD was described by its
    getters instead of its fields. SpaceAppearanceEntity came out with two
    properties where six are serialized;
  * a member annotated with @XmlTransient was described all the same.
    PdcAxisValueEntity came out with eleven properties where nine are
    serialized.

The JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,
@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of
a schema, never its visibility. As for the Jackson module bringing that
introspector, it does declare itself to the ServiceLoader, but Swagger never
asks for the modules available in the classpath.

The resolver declared here sets the introspector on a mapper of its own, the
very way the JSON codec of Silverpeas does, so that it applies to the resolution
of the schemas only. Ten business objects were documented that no endpoint ever
answers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the
like -- and they are gone now.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>c097c5d943af83fb5ce284ad45b733a9d806b761</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</affectedPath><commitId>692a545a5347eefc22d5e8f1949b6ce94151f274</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no
parameter to fill that section in, hence the document of its own declared here:
the scan completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published. The published tree is now made of the rendering page, the
specification in both of its formats, and the rendering engine.

Skipping the site altogether looked simpler but isn't an option: the deploy goal
of the site plugin reads the very same maven.site.skip property as its site
goal, so the documentation would have silently stopped being published.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>692a545a5347eefc22d5e8f1949b6ce94151f274</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>078323a23b15cb23bbbcaa797991a709645d0f7d</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, the
routes of the SCIM API not to publish, its filter and its schema resolver, the
WAR whose classes are unpacked, and the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>078323a23b15cb23bbbcaa797991a709645d0f7d</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><commitId>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Gather in core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were duplicated, one copy per project
documenting its REST API, the two being identical but for their package. They
are gathered here, beside the annotations documenting the common errors, in a
package of their own: org.silverpeas.core.rs.doc.

Their name being the same for every project now, the parent POM declares them
once for all, and nothing is left to keep the copies in step.

The counterpart is that core-rs, a module of production, depends on swagger-core
to compile them. The dependency is provided, so nothing of it is shipped, and
neither the filter nor the resolver plays any role at runtime: both are read
when generating the documentation only.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</id><msg>Gather in core-rs what generates the documentation of the REST API</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:17 +0200</date><id>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>5f5891af886c501d82d72d54f15552e3775e0ce7</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)
</comment><date>2026-09-28 14:42:28 +0200</date><id>5f5891af886c501d82d72d54f15552e3775e0ce7</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>018ed026afbb76a9ad52281cd62b8e284b9a914a</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)
</comment><date>2026-09-28 14:42:28 +0200</date><id>018ed026afbb76a9ad52281cd62b8e284b9a914a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</affectedPath><commitId>37283d39cead2166ad9483d373658c2b8e414c95</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)
</comment><date>2026-09-28 14:42:28 +0200</date><id>37283d39cead2166ad9483d373658c2b8e414c95</id><msg>Fix vulnerability #1459</msg><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>b2900e3c4738e94ab34622ee8a48197f7921a09f</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)
</comment><date>2026-09-28 14:42:28 +0200</date><id>b2900e3c4738e94ab34622ee8a48197f7921a09f</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>23acd94a451f35afaf18324777b344292593341b</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.

(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)
</comment><date>2026-09-28 14:42:28 +0200</date><id>23acd94a451f35afaf18324777b344292593341b</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>52843258f403c47fb8a0b51a75295f883fb98eda</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)
</comment><date>2026-09-28 14:42:28 +0200</date><id>52843258f403c47fb8a0b51a75295f883fb98eda</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>df92a06600aedb5b24bad01559165e839421c2b5</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:42:28 +0200</date><id>df92a06600aedb5b24bad01559165e839421c2b5</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>db15a2e30508fb101a2addaf4780cc6479eb9270</commitId><timestamp>1790599436000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:43:56 +0200</date><id>db15a2e30508fb101a2addaf4780cc6479eb9270</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>3f5875d5832af01276050f9ad75a08f7ddb4dd30</commitId><timestamp>1790608429000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:13:49 +0200</date><id>3f5875d5832af01276050f9ad75a08f7ddb4dd30</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>components-restapi/src/site/resources/index.html</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>f2fe8d93d99b4eb77e672c047d22ce154ba94673</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

The new components-restapi module gathers the web resources of the fourteen
applications into a single OpenAPI 3.1 document, rendered by Redoc and published
on its own at docs/restapi/components. It produces nothing but that
documentation and builds only with the restapi profile, from which the Smart-Doc
plugin is dropped.

All the 81 operations, spread over 70 paths and 81 schemas, are now documented.
The twenty-two operations of the almanach are inherited from the calendar
resources of Core and needed nothing: Swagger reads the annotations of the
overridden methods. The others got a summary, a success response with its
schema, and the errors they can answer, the recurring ones coming from the
@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is
brought by CommonResponsesFilter, of which this project has its own copy.

Documenting the endpoints brought several defects to light, which are fixed
here:

  * three of the four folder endpoints of Kmelia were invisible in the
    documentation. Swagger strips the regular expression of a path template, so
    {path: \d+(/\d+)*/children} was reduced to {path} and collided with the
    three other ones. The literal suffix now sits outside the template, which
    matches the very same URIs;
  * NewsResource caught back the WebApplicationException it had just thrown and
    turned it into a 503, so neither the 404 of an unknown news nor the refusal
    to delete one ever reached the requester. That refusal answers a 403 now,
    instead of a 401 without any challenge;
  * MediaResolution read the settings of the application from its enum
    constants, making the scan fail with an ExceptionInInitializerError. The
    watermark size is read lazily now;
  * five classes of Quickinfo were missing the licence header.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>f2fe8d93d99b4eb77e672c047d22ce154ba94673</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</file></path><path><editType>add</editType><file>components-restapi/pom.xml</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</file></path><path><editType>add</editType><file>components-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>59908ef73f929070700744af9c79e30cf0066fff</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire, those excluded by @XmlTransient or by an access set
to XmlAccessType.FIELD, and missing the fields that do reach it.

Same resolver as the one of Core, of which this project has its own copy, for
the very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>59908ef73f929070700744af9c79e30cf0066fff</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to
fill that section in, hence the document of its own declared here: the scan
completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published.

Same setting as the one of Core, of which this project has its own copy, for the
very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>add</editType><file>components-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>01111927bc2afba8b8a88f23247f97c2e70eab18</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, its
filter and its schema resolver, the fourteen WAR whose classes are unpacked, and
the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>01111927bc2afba8b8a88f23247f97c2e70eab18</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>021fe614496d0adf069aaade785f13438a7998ca</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were copied here from Silverpeas Core,
where they now sit in a package of their own, org.silverpeas.core.rs.doc,
alongside the annotations documenting the common errors. The copies are dropped
and the parent POM declares the classes of core-rs instead.

The annotations documenting the common errors follow them: the endpoints of the
applications refer them at their new place.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>021fe614496d0adf069aaade785f13438a7998ca</id><msg>Take from core-rs what generates the documentation of the REST API</msg><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>9d3490bf7cd64723cdac38d15472d03679bb8950</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:34 +0200</date><id>9d3490bf7cd64723cdac38d15472d03679bb8950</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)
</comment><date>2026-09-28 14:43:22 +0200</date><id>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)
</comment><date>2026-09-28 14:43:22 +0200</date><id>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>03b14dd2f030f634a99944c3272b31500811242f</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)
</comment><date>2026-09-28 14:43:22 +0200</date><id>03b14dd2f030f634a99944c3272b31500811242f</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>0b6076009ffb133c105e4861267e1cda62176d78</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.

(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>0b6076009ffb133c105e4861267e1cda62176d78</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.

(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><commitId>f371b6452d9360af47926ebccceba45e05d252ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)
</comment><date>2026-09-28 14:43:22 +0200</date><id>f371b6452d9360af47926ebccceba45e05d252ca</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><commitId>bb7f36a57f96d33b8bd92d826056770e3c14e04c</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)
</comment><date>2026-09-28 14:43:22 +0200</date><id>bb7f36a57f96d33b8bd92d826056770e3c14e04c</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>eca5145d6d01f77adce83ef714742073585675ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:43:22 +0200</date><id>eca5145d6d01f77adce83ef714742073585675ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></previousBuild></lastCompletedBuild><lastFailedBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='hudson.model.CauseAction'><cause _class='hudson.model.Cause$UserIdCause'><shortDescription>Démarré par l'utilisateur Miguel Moquillon</shortDescription><userId>mmoquillon</userId><userName>Miguel Moquillon</userName></cause></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><building>false</building><displayName>#1162</displayName><duration>3135500</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy #1162</fullDisplayName><id>1162</id><keepLog>false</keepLog><number>1162</number><queueId>63310</queueId><result>FAILURE</result><timestamp>1790584035065</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1162/</url><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><nextBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></nextBuild><previousBuild><number>1161</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1161/</url></previousBuild></lastFailedBuild><lastStableBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0l2pebQNaPUmG7crv</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0uxyCkj6CGoBn7yyg</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260930</displayName><duration>24065087</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260930</fullDisplayName><id>1164</id><keepLog>false</keepLog><number>1164</number><queueId>63961</queueId><result>SUCCESS</result><timestamp>1790789040596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/site/resources/index.html</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>ec9caee6b1242b8d5893ed5ece0884304d811cb0</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

Smart-Doc parses the sources with QDox and chokes on constructs Silverpeas
relies on, silently reporting a success while producing an incomplete
documentation. Swagger scans the compiled classes by reflection and understands
the JAX-RS annotations, so the whole REST API is covered.

The new core-restapi module gathers the web resources of all the modules into a
single OpenAPI 3.1 document, rendered by Redoc and published on its own at
docs/restapi/core. It produces nothing but that documentation and builds only
with the restapi profile, from which the Smart-Doc plugin is dropped.

All the 217 operations, spread over 168 paths and 86 schemas, are now
documented: a summary, a success response with its schema, and the errors the
endpoint can answer. The responses common to several endpoints are declared once
for all:

  * @Authenticated and @Authorized, besides the security schemes they already
    described, bring the 401 and 403 responses of the protected resources;
  * the 503 is brought by CommonResponsesFilter, applied once the specification
    has been figured out. It cannot come from another meta-annotation of the web
    resources: at class level Swagger returns the responses of the first
    meta-annotation declaring some instead of merging them all, so a second one
    would silently discard the responses of @Authenticated and @Authorized;
  * the recurring 404, 400 and 409 are factored out into the @NotFound,
    @BadRequest and @Conflict annotations of the new annotation.doc package.
    Contrary to the class level one, the method level lookup of Swagger does
    merge, but the description of such an annotation takes precedence over the
    one an endpoint would declare for the same status code, hence an endpoint
    needing another wording must not be annotated.

Documenting the endpoints brought several defects to light, which are fixed
here: the wrong descriptions of the personal space endpoints of SpaceResource, a
test endpoint left over in CipherKeyResource, and the conflicting setters of
AbstractI18NBean for the translations property, which made the scan fail.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>ec9caee6b1242b8d5893ed5ece0884304d811cb0</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</file></path><path><editType>add</editType><file>core-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</file></path><path><editType>add</editType><file>core-restapi/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><commitId>c097c5d943af83fb5ce284ad45b733a9d806b761</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire and missing others that do:

  * an entity whose access is set to XmlAccessType.FIELD was described by its
    getters instead of its fields. SpaceAppearanceEntity came out with two
    properties where six are serialized;
  * a member annotated with @XmlTransient was described all the same.
    PdcAxisValueEntity came out with eleven properties where nine are
    serialized.

The JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,
@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of
a schema, never its visibility. As for the Jackson module bringing that
introspector, it does declare itself to the ServiceLoader, but Swagger never
asks for the modules available in the classpath.

The resolver declared here sets the introspector on a mapper of its own, the
very way the JSON codec of Silverpeas does, so that it applies to the resolution
of the schemas only. Ten business objects were documented that no endpoint ever
answers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the
like -- and they are gone now.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>c097c5d943af83fb5ce284ad45b733a9d806b761</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</affectedPath><commitId>692a545a5347eefc22d5e8f1949b6ce94151f274</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no
parameter to fill that section in, hence the document of its own declared here:
the scan completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published. The published tree is now made of the rendering page, the
specification in both of its formats, and the rendering engine.

Skipping the site altogether looked simpler but isn't an option: the deploy goal
of the site plugin reads the very same maven.site.skip property as its site
goal, so the documentation would have silently stopped being published.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>692a545a5347eefc22d5e8f1949b6ce94151f274</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>078323a23b15cb23bbbcaa797991a709645d0f7d</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, the
routes of the SCIM API not to publish, its filter and its schema resolver, the
WAR whose classes are unpacked, and the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>078323a23b15cb23bbbcaa797991a709645d0f7d</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><commitId>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Gather in core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were duplicated, one copy per project
documenting its REST API, the two being identical but for their package. They
are gathered here, beside the annotations documenting the common errors, in a
package of their own: org.silverpeas.core.rs.doc.

Their name being the same for every project now, the parent POM declares them
once for all, and nothing is left to keep the copies in step.

The counterpart is that core-rs, a module of production, depends on swagger-core
to compile them. The dependency is provided, so nothing of it is shipped, and
neither the filter nor the resolver plays any role at runtime: both are read
when generating the documentation only.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</id><msg>Gather in core-rs what generates the documentation of the REST API</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:17 +0200</date><id>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>5f5891af886c501d82d72d54f15552e3775e0ce7</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)
</comment><date>2026-09-28 14:42:28 +0200</date><id>5f5891af886c501d82d72d54f15552e3775e0ce7</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>018ed026afbb76a9ad52281cd62b8e284b9a914a</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)
</comment><date>2026-09-28 14:42:28 +0200</date><id>018ed026afbb76a9ad52281cd62b8e284b9a914a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</affectedPath><commitId>37283d39cead2166ad9483d373658c2b8e414c95</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)
</comment><date>2026-09-28 14:42:28 +0200</date><id>37283d39cead2166ad9483d373658c2b8e414c95</id><msg>Fix vulnerability #1459</msg><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>b2900e3c4738e94ab34622ee8a48197f7921a09f</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)
</comment><date>2026-09-28 14:42:28 +0200</date><id>b2900e3c4738e94ab34622ee8a48197f7921a09f</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>23acd94a451f35afaf18324777b344292593341b</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.

(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)
</comment><date>2026-09-28 14:42:28 +0200</date><id>23acd94a451f35afaf18324777b344292593341b</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>52843258f403c47fb8a0b51a75295f883fb98eda</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)
</comment><date>2026-09-28 14:42:28 +0200</date><id>52843258f403c47fb8a0b51a75295f883fb98eda</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>df92a06600aedb5b24bad01559165e839421c2b5</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:42:28 +0200</date><id>df92a06600aedb5b24bad01559165e839421c2b5</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>db15a2e30508fb101a2addaf4780cc6479eb9270</commitId><timestamp>1790599436000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:43:56 +0200</date><id>db15a2e30508fb101a2addaf4780cc6479eb9270</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>3f5875d5832af01276050f9ad75a08f7ddb4dd30</commitId><timestamp>1790608429000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:13:49 +0200</date><id>3f5875d5832af01276050f9ad75a08f7ddb4dd30</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>components-restapi/src/site/resources/index.html</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>f2fe8d93d99b4eb77e672c047d22ce154ba94673</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

The new components-restapi module gathers the web resources of the fourteen
applications into a single OpenAPI 3.1 document, rendered by Redoc and published
on its own at docs/restapi/components. It produces nothing but that
documentation and builds only with the restapi profile, from which the Smart-Doc
plugin is dropped.

All the 81 operations, spread over 70 paths and 81 schemas, are now documented.
The twenty-two operations of the almanach are inherited from the calendar
resources of Core and needed nothing: Swagger reads the annotations of the
overridden methods. The others got a summary, a success response with its
schema, and the errors they can answer, the recurring ones coming from the
@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is
brought by CommonResponsesFilter, of which this project has its own copy.

Documenting the endpoints brought several defects to light, which are fixed
here:

  * three of the four folder endpoints of Kmelia were invisible in the
    documentation. Swagger strips the regular expression of a path template, so
    {path: \d+(/\d+)*/children} was reduced to {path} and collided with the
    three other ones. The literal suffix now sits outside the template, which
    matches the very same URIs;
  * NewsResource caught back the WebApplicationException it had just thrown and
    turned it into a 503, so neither the 404 of an unknown news nor the refusal
    to delete one ever reached the requester. That refusal answers a 403 now,
    instead of a 401 without any challenge;
  * MediaResolution read the settings of the application from its enum
    constants, making the scan fail with an ExceptionInInitializerError. The
    watermark size is read lazily now;
  * five classes of Quickinfo were missing the licence header.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>f2fe8d93d99b4eb77e672c047d22ce154ba94673</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</file></path><path><editType>add</editType><file>components-restapi/pom.xml</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</file></path><path><editType>add</editType><file>components-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>59908ef73f929070700744af9c79e30cf0066fff</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire, those excluded by @XmlTransient or by an access set
to XmlAccessType.FIELD, and missing the fields that do reach it.

Same resolver as the one of Core, of which this project has its own copy, for
the very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>59908ef73f929070700744af9c79e30cf0066fff</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to
fill that section in, hence the document of its own declared here: the scan
completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published.

Same setting as the one of Core, of which this project has its own copy, for the
very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>add</editType><file>components-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>01111927bc2afba8b8a88f23247f97c2e70eab18</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, its
filter and its schema resolver, the fourteen WAR whose classes are unpacked, and
the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>01111927bc2afba8b8a88f23247f97c2e70eab18</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>021fe614496d0adf069aaade785f13438a7998ca</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were copied here from Silverpeas Core,
where they now sit in a package of their own, org.silverpeas.core.rs.doc,
alongside the annotations documenting the common errors. The copies are dropped
and the parent POM declares the classes of core-rs instead.

The annotations documenting the common errors follow them: the endpoints of the
applications refer them at their new place.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>021fe614496d0adf069aaade785f13438a7998ca</id><msg>Take from core-rs what generates the documentation of the REST API</msg><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>9d3490bf7cd64723cdac38d15472d03679bb8950</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:34 +0200</date><id>9d3490bf7cd64723cdac38d15472d03679bb8950</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)
</comment><date>2026-09-28 14:43:22 +0200</date><id>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)
</comment><date>2026-09-28 14:43:22 +0200</date><id>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>03b14dd2f030f634a99944c3272b31500811242f</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)
</comment><date>2026-09-28 14:43:22 +0200</date><id>03b14dd2f030f634a99944c3272b31500811242f</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>0b6076009ffb133c105e4861267e1cda62176d78</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.

(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>0b6076009ffb133c105e4861267e1cda62176d78</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.

(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><commitId>f371b6452d9360af47926ebccceba45e05d252ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)
</comment><date>2026-09-28 14:43:22 +0200</date><id>f371b6452d9360af47926ebccceba45e05d252ca</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><commitId>bb7f36a57f96d33b8bd92d826056770e3c14e04c</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)
</comment><date>2026-09-28 14:43:22 +0200</date><id>bb7f36a57f96d33b8bd92d826056770e3c14e04c</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>eca5145d6d01f77adce83ef714742073585675ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:43:22 +0200</date><id>eca5145d6d01f77adce83ef714742073585675ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></previousBuild></lastStableBuild><lastSuccessfulBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.TimerTrigger$TimerTriggerCause'><shortDescription>Lancé par une alarme périodique</shortDescription></cause></action><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><branch><SHA1>3f5875d5832af01276050f9ad75a08f7ddb4dd30</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><branch><SHA1>eca5145d6d01f77adce83ef714742073585675ca</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1164</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0l2pebQNaPUmG7crv</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Core2&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarAnalysisAction'><ceTaskId>AaD0uxyCkj6CGoBn7yyg</ceTaskId><installationName>Silverpeas SonarCloud</installationName><installationUrl>https://sonarcloud.io</installationUrl><new>true</new><serverUrl>https://sonarcloud.io</serverUrl><skipped>false</skipped><sonarqubeDashboardUrl>https://sonarcloud.io/dashboard?id=Silverpeas_Silverpeas-Components&amp;branch=master</sonarqubeDashboardUrl></action><action></action><action></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.sonar.action.SonarBuildBadgeAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><artifact><displayPath>build.yaml</displayPath><fileName>build.yaml</fileName><relativePath>target/build.yaml</relativePath></artifact><building>false</building><displayName>6.5-build260930</displayName><duration>24065087</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy 6.5-build260930</fullDisplayName><id>1164</id><keepLog>false</keepLog><number>1164</number><queueId>63961</queueId><result>SUCCESS</result><timestamp>1790789040596</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1164/</url><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/site/resources/index.html</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>ec9caee6b1242b8d5893ed5ece0884304d811cb0</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

Smart-Doc parses the sources with QDox and chokes on constructs Silverpeas
relies on, silently reporting a success while producing an incomplete
documentation. Swagger scans the compiled classes by reflection and understands
the JAX-RS annotations, so the whole REST API is covered.

The new core-restapi module gathers the web resources of all the modules into a
single OpenAPI 3.1 document, rendered by Redoc and published on its own at
docs/restapi/core. It produces nothing but that documentation and builds only
with the restapi profile, from which the Smart-Doc plugin is dropped.

All the 217 operations, spread over 168 paths and 86 schemas, are now
documented: a summary, a success response with its schema, and the errors the
endpoint can answer. The responses common to several endpoints are declared once
for all:

  * @Authenticated and @Authorized, besides the security schemes they already
    described, bring the 401 and 403 responses of the protected resources;
  * the 503 is brought by CommonResponsesFilter, applied once the specification
    has been figured out. It cannot come from another meta-annotation of the web
    resources: at class level Swagger returns the responses of the first
    meta-annotation declaring some instead of merging them all, so a second one
    would silently discard the responses of @Authenticated and @Authorized;
  * the recurring 404, 400 and 409 are factored out into the @NotFound,
    @BadRequest and @Conflict annotations of the new annotation.doc package.
    Contrary to the class level one, the method level lookup of Swagger does
    merge, but the description of such an annotation takes precedence over the
    one an endpoint would declare for the same status code, hence an endpoint
    needing another wording must not be annotated.

Documenting the endpoints brought several defects to light, which are fixed
here: the wrong descriptions of the personal space endpoints of SpaceResource, a
test endpoint left over in CipherKeyResource, and the conflicting setters of
AbstractI18NBean for the translations property, which made the scan fail.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>ec9caee6b1242b8d5893ed5ece0884304d811cb0</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/RelationResource.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authenticated.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/cache/VolatileCacheResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResourceCreator.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserGroupProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/socialnetwork/invitation/InvitationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/search/SearchResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/security/CipherKeyResource.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/i18n/AbstractI18NBean.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/FilteredPdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/workflow/ReplacementResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/wysiwyg/WysiwygEditorConfigResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/session/SilverpeasUserSessionTokenResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscribeResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/TicketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/rating/RatingResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/mylinks/MyLinksResource.java</file></path><path><editType>add</editType><file>core-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/LogResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/UnsubscribeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/AttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/thesaurus/ThesaurusResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/UserProfileResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/EmbedMediaViewerResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/PublicationResource.java</file></path><path><editType>add</editType><file>core-restapi/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/language/LanguageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/variables/VariablesResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/upload/FileUploadResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/selection/SelectionBasketResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/sharing/SharingResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/publication/SharedPublicationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/bundle/BundleResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentsResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/profile/AuthenticationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SharedAttachmentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/util/logging/SilverLoggerConfigurationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/attachment/SimpleDocumentListResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/AbstractNodeResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/preferences/MyPreferencesResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><commitId>c097c5d943af83fb5ce284ad45b733a9d806b761</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire and missing others that do:

  * an entity whose access is set to XmlAccessType.FIELD was described by its
    getters instead of its fields. SpaceAppearanceEntity came out with two
    properties where six are serialized;
  * a member annotated with @XmlTransient was described all the same.
    PdcAxisValueEntity came out with eleven properties where nine are
    serialized.

The JAXBAnnotationsHelper of Swagger is of no help here: it reads @XmlElement,
@XmlElementWrapper and @XmlAttribute only, and only to feed the XML metadata of
a schema, never its visibility. As for the Jackson module bringing that
introspector, it does declare itself to the ServiceLoader, but Swagger never
asks for the modules available in the classpath.

The resolver declared here sets the introspector on a mapper of its own, the
very way the JSON codec of Silverpeas does, so that it applies to the resolution
of the schemas only. Ten business objects were documented that no endpoint ever
answers -- User, UserDetail, Domain, Quota, SettingBundle, PdcPosition and the
like -- and they are gone now.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>c097c5d943af83fb5ce284ad45b733a9d806b761</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>add</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</affectedPath><commitId>692a545a5347eefc22d5e8f1949b6ce94151f274</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it, and Redoc did. Contrary to the plugin of SmallRye, the one of Swagger has no
parameter to fill that section in, hence the document of its own declared here:
the scan completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published. The published tree is now made of the rendering page, the
specification in both of its formats, and the rendering engine.

Skipping the site altogether looked simpler but isn't an option: the deploy goal
of the site plugin reads the very same maven.site.skip property as its site
goal, so the documentation would have silently stopped being published.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>692a545a5347eefc22d5e8f1949b6ce94151f274</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthorizedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/Authorized.java</file></path><path><editType>add</editType><file>core-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/processing/AuthenticatedAnnotationProcessor.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>078323a23b15cb23bbbcaa797991a709645d0f7d</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, the
routes of the SCIM API not to publish, its filter and its schema resolver, the
WAR whose classes are unpacked, and the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>078323a23b15cb23bbbcaa797991a709645d0f7d</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</affectedPath><affectedPath>core-web/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>core-restapi/pom.xml</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</affectedPath><affectedPath>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</affectedPath><affectedPath>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</affectedPath><affectedPath>core-rs/pom.xml</affectedPath><commitId>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Gather in core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were duplicated, one copy per project
documenting its REST API, the two being identical but for their package. They
are gathered here, beside the annotations documenting the common errors, in a
package of their own: org.silverpeas.core.rs.doc.

Their name being the same for every project now, the parent POM declares them
once for all, and nothing is left to keep the copies in step.

The counterpart is that core-rs, a module of production, depends on swagger-core
to compile them. The dependency is provided, so nothing of it is shipped, and
neither the filter nor the resolver plays any role at runtime: both are read
when generating the documentation only.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:17 +0200</date><id>b738adf1743bdd89b3f676bf5dcc7acd6ccf2d9a</id><msg>Gather in core-rs what generates the documentation of the REST API</msg><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcClassificationResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/Conflict.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/Conflict.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/media/streaming/StreamingPlayerResource.java</file></path><path><editType>edit</editType><file>core-web/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/comment/CommentResource.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/MessageResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/password/PasswordResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/ICalendarResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/ComponentResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/calendar/CalendarResource.java</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/BadRequest.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/DocumentViewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/look/DisplayResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcPredefinedClassificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/notification/user/InboxUserNotificationResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/documenttemplate/DocumentTemplateResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/admin/SpaceResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/contribution/ContributionContentResource.java</file></path><path><editType>edit</editType><file>core-restapi/pom.xml</file></path><path><editType>delete</editType><file>core-rs/src/main/java/org/silverpeas/core/web/rs/annotation/doc/NotFound.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/reminder/ReminderResource.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/NotFound.java</file></path><path><editType>add</editType><file>core-rs/src/main/java/org/silverpeas/core/rs/doc/BadRequest.java</file></path><path><editType>delete</editType><file>core-restapi/src/main/java/org/silverpeas/core/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/viewer/PreviewResource.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/subscribe/SubscriptionResource.java</file></path><path><editType>edit</editType><file>core-rs/pom.xml</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/pdc/PdcResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-restapi/pom.xml</affectedPath><commitId>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</commitId><timestamp>1790597537000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:17 +0200</date><id>d41b4c150a336e2cb3019a2b3687c5a403cba3d4</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>core-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>5f5891af886c501d82d72d54f15552e3775e0ce7</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460

(GitHub issues, reported against 6.4.6)

The three reported stored XSS rely on an event callback attribute carried by an
element the browser fails to load on purpose. Such a declaration was detected by
the \s+on\w+\s*= pattern, which expects a whitespace before the attribute name.
According to the HTML tokenizer, an attribute name is also expected right after
the closing quote of the previous attribute value (a
missing-whitespace-between-attributes parse error, whose recovery is mandated by
the specification) and right after a solidus. So the following did declare an
onerror callback the browsers do run, while going through the filter:

  &lt;img src="x"onerror=alert(1)&gt;

The pattern now accepts these separators as well.

Note this filter is an input guard, not an output encoding: it narrows the
reachability of the three flaws but it doesn't fix the rendering code itself.

MassiveWebSecurityFilterOnReportedXssIT covers the payloads of the three reports
on their actual endpoints and parameters, including when they are submitted as
multipart/form-data streams as the genuine forms do. It also delimits the
multipart exemption, which applies to the webPages component only.

TestHttpRequest.getContentType() returned null whatever the headers set on the
stub, which made the multipart branch untestable.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 81589f6134e8e337c16a6c390b2d804e78006f8f)
</comment><date>2026-09-28 14:42:28 +0200</date><id>5f5891af886c501d82d72d54f15552e3775e0ce7</id><msg>Harden the detection of the event callbacks against the vulnerabilities #1458, #1459 and #1460</msg><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path><path><editType>add</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web-test/src/main/java/org/silverpeas/web/test/stub/TestHttpRequest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>018ed026afbb76a9ad52281cd62b8e284b9a914a</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1458

(GitHub issue, reported against 6.4.6)

The login question, which any authenticated user sets from their profile, was
printed raw by a JSP scriptlet on the password reminder page, an anonymous one.
Any script stored there was then run in the browser of every visitor of that
page, without any login required from them. The answer to that question, itself
a credential, is asked on the very same page.

The value is now HTML encoded on output, through a c:out tag. Doing so on the
rendering side rather than on the writing one closes both the ways the field is
fed: MyProfilRequestRouter, which the report points at, but also
ValidationQuestionHandler, which stores the question of the ValidateQuestion
function with no more filtering. It also neutralizes the values already stored.

The login of the hidden field below is encoded as well. It comes from a lookup
in the database and not from the request parameter, so exploiting it would
require a login holding a quote, but the encoding costs nothing here.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 457be5fa780ce2656d7104f31515ea7064e2fbf6)
</comment><date>2026-09-28 14:42:28 +0200</date><id>018ed026afbb76a9ad52281cd62b8e284b9a914a</id><msg>Fix vulnerability #1458</msg><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</affectedPath><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</affectedPath><affectedPath>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</affectedPath><affectedPath>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</affectedPath><affectedPath>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</affectedPath><commitId>37283d39cead2166ad9483d373658c2b8e414c95</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1459

(GitHub issue, reported against 6.4.6)

The WYSIWYG content of a form field was written into the response as raw HTML by
WysiwygFCKFieldDisplayer, so any script stored by the writer of a whitePages
card was run in the browser of every user viewing it. The same held for the
content of a publication, rendered by WysiwygContentRenderer, and for the two
export paths, none of which was reported.

Such a content is sanitized now, by the new SanitizeForRenderingDirective.
Unlike SanitizeDirective, which keeps only a restricted set of safe elements and
is left untouched for the contents extracted out of Silverpeas, this one keeps
the content as it is and drops only what can act on the visitor's browser:

- the elements able to run code or to take over the document, with their
  content;
- the event callback attributes, whatever the element carrying them;
- the attributes referring a URL with a scripting scheme;
- the iframes and the media whose source isn't allowed.

This is deliberate: the WYSIWYG editor is set up to accept any content
(config.allowedContent = true in silverconfig.js), so an allow list applied at
rendering time would be narrower than what the users are entitled to write. It
would in particular have dropped the media produced by the video and html5audio
plugins and the rel attribute the userzoom and identitycard ones rely upon.

The parsing is delegated to the HTML tokenizer of the OWASP sanitizer, so the
content is read the way a browser reads it and the dropping can't be dodged by
playing with the HTML syntax.

The rule deciding whether the source of an iframe is allowed moves to the new
EmbeddedSourceValidator class, so that the filtering of the incoming requests
and this sanitization agree on it. It now serves the media as well, through the
new security.external.media.hosts.allowed property. That property is shipped
with the * value, which allows any host and hence preserves the behaviour of the
previous versions; setting it empty restricts the media to the ones Silverpeas
hosts itself. The inlined images are kept whatever it is, being carried by the
content itself.

The mail path is deliberately left out: its images are referred by cid URLs,
which such a sanitization drops, and its content isn't rendered in the
Silverpeas origin anyway.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit 2961a40c81708375b2136cfa18f7c5f5e1d97321)
</comment><date>2026-09-28 14:42:28 +0200</date><id>37283d39cead2166ad9483d373658c2b8e414c95</id><msg>Fix vulnerability #1459</msg><path><editType>add</editType><file>core-api/src/main/java/org/silverpeas/core/security/html/EmbeddedSourceValidator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/test/LibCoreWarBuilder.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentRenderer.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/form/displayers/WysiwygFCKFieldDisplayer.java</file></path><path><editType>edit</editType><file>core-library/src/test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformerTest.java</file></path><path><editType>add</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/IFrameChecker.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/control/PublicationsTypeManager.java</file></path><path><editType>edit</editType><file>core-services/importExport/src/main/java/org/silverpeas/core/importexport/report/HtmlExportPublicationGenerator.java</file></path><path><editType>edit</editType><file>core-library/src/integration-test/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygControllerIT.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/WysiwygContentTransformer.java</file></path><path><editType>edit</editType><file>core-api/src/main/java/org/silverpeas/core/util/security/SecuritySettings.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</affectedPath><commitId>b2900e3c4738e94ab34622ee8a48197f7921a09f</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue, reported against 6.4.6)

Let the callers of HttpUtil complete the HTTP client.

Fixing that vulnerability requires the gallery component to request the image of
a watermark with a connection timeout and without following the redirections,
the latter being able to escape the verification of the address being requested.

httpClientBuilder() gives the builder of the HTTP client, already configured
with the proxy of Silverpeas, so that such a caller can complete the
configuration without having to duplicate that of the proxy. httpClient() now
delegates to it and is unchanged for its own callers.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 16cff5ecd5e217798d51ebe7f5a97103f4d901b0)
</comment><date>2026-09-28 14:42:28 +0200</date><id>b2900e3c4738e94ab34622ee8a48197f7921a09f</id><msg>Fix vulnerability #1461</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/util/HttpUtil.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</affectedPath><affectedPath>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</affectedPath><commitId>23acd94a451f35afaf18324777b344292593341b</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741

Both report a stored XSS through the name of an uploaded file, one from the
document management and the other from the image upload of the WYSIWYG editor.
They share their cause: the name is written as an HTML content by the upload
widget, whereas it is carried by the request and escaped on the sending side
only, which protects from nothing as a request can be forged.

The name is now set as a text. Note the formatted size which followed it was
already not displayed, html() taking a single argument, so the display is left
unchanged.

A scripting scheme given as the value of an attribute is detected as well by
MassiveWebSecurityFilter. Such a declaration holds no on prefix and was
therefore going through, and the colon introducing it is accepted written as
the character itself or as any of the HTML entities standing for it, as the
reported payload uses "javascript&amp;colon;". The data scheme is deliberately left
out: the contents do embed their inlined images with it.

(cherry picked from commit 4f92097f60d0d6e8072815cf5a77093d3f19f9e3)
</comment><date>2026-09-28 14:42:28 +0200</date><id>23acd94a451f35afaf18324777b344292593341b</id><msg>Fix the vulnerabilities CVE-2026-78738 and CVE-2026-78741</msg><path><editType>edit</editType><file>core-war/src/main/webapp/util/javaScript/silverpeas-fileUpload.js</file></path><path><editType>edit</editType><file>core-web/src/integration-test/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilterOnReportedXssIT.java</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/web/filter/MassiveWebSecurityFilter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</affectedPath><affectedPath>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</affectedPath><affectedPath>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</affectedPath><affectedPath>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</affectedPath><commitId>52843258f403c47fb8a0b51a75295f883fb98eda</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Sort only the nodes of the component instance being administrated

The sorting of the nodes was granted against the component instance referred by
the URL of the REST service, whereas the nodes to sort were taken from the
request body, each of them carrying the component instance it belongs to. An
administrator of any instance could hence ask to sort the nodes of another one.

The nodes are now identified within the instance of the URL, the one the
authorization has been checked against. Taking that instance from the body
brought nothing: the sorting applies by nature to the instance administrated.

That wasn't enough though. NodeDAO was updating the order of a node by its
identifier only, whereas such an identifier isn't unique by itself: the root
node of every component instance is numbered 0, and the ones below it can bear
the same numbers from an instance to another. So the instance of the node is
now part of the criteria. Beyond the authorization, this was a defect on its
own: sorting the nodes of an instance was renumbering the nodes of the other
ones bearing the same identifiers, whoever asked for that sorting.

NodeSortingIT covers the sorting of the nodes of an instance and the isolation
of the other instances from it, in both directions.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e7028e01e7261c16803ee20f841763ef5b84ab7b)
</comment><date>2026-09-28 14:42:28 +0200</date><id>52843258f403c47fb8a0b51a75295f883fb98eda</id><msg>Sort only the nodes of the component instance being administrated</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/node/dao/NodeDAO.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/resources/org/silverpeas/core/node/dao/nodes-sorting-dataset.sql</file></path><path><editType>edit</editType><file>core-web/src/main/java/org/silverpeas/core/webapi/node/ListNodeResource.java</file></path><path><editType>add</editType><file>core-library/src/integration-test/java/org/silverpeas/core/node/dao/NodeSortingIT.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</affectedPath><affectedPath>core-war/src/main/webapp/defaultLoginQuestion.jsp</affectedPath><commitId>df92a06600aedb5b24bad01559165e839421c2b5</commitId><timestamp>1790599348000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:42:28 +0200</date><id>df92a06600aedb5b24bad01559165e839421c2b5</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/contribution/content/wysiwyg/service/directive/SanitizeForRenderingDirective.java</file></path><path><editType>edit</editType><file>core-war/src/main/webapp/defaultLoginQuestion.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</affectedPath><commitId>db15a2e30508fb101a2addaf4780cc6479eb9270</commitId><timestamp>1790599436000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Now the parameter security.external.media.hosts.allowed is empty.

This means all hosts out of Silverpeas will be refused in HTML media
tags (video, iframe, img, ...)
</comment><date>2026-09-28 14:43:56 +0200</date><id>db15a2e30508fb101a2addaf4780cc6479eb9270</id><msg>Now the parameter security.external.media.hosts.allowed is empty.</msg><path><editType>edit</editType><file>core-configuration/src/main/config/properties/org/silverpeas/util/security.properties</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</affectedPath><affectedPath>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</affectedPath><commitId>3f5875d5832af01276050f9ad75a08f7ddb4dd30</commitId><timestamp>1790608429000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@silverpeas.com</authorEmail><comment>Fix bug-15488
</comment><date>2026-09-28 17:13:49 +0200</date><id>3f5875d5832af01276050f9ad75a08f7ddb4dd30</id><msg>Fix bug-15488</msg><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/tika/TikaParser.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/model/IndexManager.java</file></path><path><editType>edit</editType><file>core-library/src/main/java/org/silverpeas/core/index/indexing/parser/Parser.java</file></path></item><kind>git</kind></changeSet><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>components-restapi/src/site/resources/index.html</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</affectedPath><affectedPath>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>f2fe8d93d99b4eb77e672c047d22ce154ba94673</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Generate the documentation of the REST API with Swagger instead of Smart-Doc

The new components-restapi module gathers the web resources of the fourteen
applications into a single OpenAPI 3.1 document, rendered by Redoc and published
on its own at docs/restapi/components. It produces nothing but that
documentation and builds only with the restapi profile, from which the Smart-Doc
plugin is dropped.

All the 81 operations, spread over 70 paths and 81 schemas, are now documented.
The twenty-two operations of the almanach are inherited from the calendar
resources of Core and needed nothing: Swagger reads the annotations of the
overridden methods. The others got a summary, a success response with its
schema, and the errors they can answer, the recurring ones coming from the
@NotFound and @Conflict annotations of Core. The 503 common to every endpoint is
brought by CommonResponsesFilter, of which this project has its own copy.

Documenting the endpoints brought several defects to light, which are fixed
here:

  * three of the four folder endpoints of Kmelia were invisible in the
    documentation. Swagger strips the regular expression of a path template, so
    {path: \d+(/\d+)*/children} was reduced to {path} and collided with the
    three other ones. The literal suffix now sits outside the template, which
    matches the very same URIs;
  * NewsResource caught back the WebApplicationException it had just thrown and
    turned it into a 503, so neither the 404 of an unknown news nor the refusal
    to delete one ever reached the requester. That refusal answers a 403 now,
    instead of a 401 without any challenge;
  * MediaResolution read the settings of the application from its enum
    constants, making the scan fail with an ExceptionInInitializerError. The
    watermark size is read lazily now;
  * five classes of Quickinfo were missing the licence header.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>f2fe8d93d99b4eb77e672c047d22ce154ba94673</id><msg>Generate the documentation of the REST API with Swagger instead of Smart-Doc</msg><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/main/java/org/silverpeas/components/quickinfo/NewsSort.java</file></path><path><editType>add</editType><file>components-restapi/pom.xml</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/AbstractNewsResource.java</file></path><path><editType>add</editType><file>components-restapi/src/site/resources/index.html</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-library/src/integration-test/java/org/silverpeas/components/quickinfo/repository/NewsRepositoryIT.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/constant/MediaResolution.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/TickerResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/FolderResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>59908ef73f929070700744af9c79e30cf0066fff</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Make the schema resolver of Swagger aware of the JAXB annotations

The resolver figures the properties of a web entity out with a plain Jackson
object mapper, whereas Silverpeas serializes them with the introspector of the
JAXB annotations. The generated schemas were therefore describing properties
that never reach the wire, those excluded by @XmlTransient or by an access set
to XmlAccessType.FIELD, and missing the fields that do reach it.

Same resolver as the one of Core, of which this project has its own copy, for
the very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>59908ef73f929070700744af9c79e30cf0066fff</id><msg>Make the schema resolver of Swagger aware of the JAXB annotations</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>add</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/src/main/openapi/openapi.yaml</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Publish nothing but the documentation of the REST API

The generated specification declared no info section, which OpenAPI requires. A
renderer refuses to display such a document, whatever the quality of the rest of
it. Contrary to the plugin of SmallRye, the one of Swagger has no parameter to
fill that section in, hence the document of its own declared here: the scan
completes it, and Maven fills its version in.

Besides the documentation of the REST API, the module was publishing the site
Maven builds for it: the reports about the dependencies, the SCM, the javadoc of
a module that has almost no source. Those reports aren't produced any more, and
what the site brings along -- its decoration and its sitemap, of no use to the
rendering page -- is dropped once the site has been built, before it gets
published.

Same setting as the one of Core, of which this project has its own copy, for the
very reason its filter completing the responses has one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>ae522b0fb3a88fbb36407023c62f0c096c2a3ab3</id><msg>Publish nothing but the documentation of the REST API</msg><path><editType>add</editType><file>components-restapi/src/main/openapi/openapi.yaml</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>01111927bc2afba8b8a88f23247f97c2e70eab18</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from the parent POM what doesn't depend on the project

The version of Redoc, swagger-core, the base document carrying the info section,
the output of the generated specification and the binding of the resolve goal of
Swagger, along with the execution stripping the Maven site, are now managed by
the parent POM. The module keeps what is its own: the packages to scan, its
filter and its schema resolver, the fourteen WAR whose classes are unpacked, and
the URL the documentation is published at.

It also keeps the setting silencing the reports of the site plugin: that plugin
is declared by the root POM of the project, so managing the setting in the
parent would make every Maven site of Silverpeas lose its reports.

This takes effect once the parent POM is released: the project still refers to
the last released one.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>01111927bc2afba8b8a88f23247f97c2e70eab18</id><msg>Take from the parent POM what doesn't depend on the project</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</affectedPath><affectedPath>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</affectedPath><affectedPath>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</affectedPath><affectedPath>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</affectedPath><affectedPath>pom.xml</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><affectedPath>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</affectedPath><affectedPath>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</affectedPath><affectedPath>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</affectedPath><affectedPath>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>components-restapi/pom.xml</affectedPath><commitId>021fe614496d0adf069aaade785f13438a7998ca</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take from core-rs what generates the documentation of the REST API

The filter completing the responses of every endpoint and the resolver reading
the JAXB annotations of the web entities were copied here from Silverpeas Core,
where they now sit in a package of their own, org.silverpeas.core.rs.doc,
alongside the annotations documenting the common errors. The copies are dropped
and the parent POM declares the classes of core-rs instead.

The annotations documenting the common errors follow them: the endpoints of the
applications refer them at their new place.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
</comment><date>2026-09-28 14:12:34 +0200</date><id>021fe614496d0adf069aaade785f13438a7998ca</id><msg>Take from core-rs what generates the documentation of the REST API</msg><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/QuestionResource.java</file></path><path><editType>edit</editType><file>resourcesManager/resourcesManager-war/src/main/java/org/silverpeas/components/resourcesmanager/web/ResourceManagerResource.java</file></path><path><editType>edit</editType><file>rssAggregator/rssAggregator-war/src/main/java/org/silverpeas/components/rssaggregator/web/RSSResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityOfUsersResource.java</file></path><path><editType>edit</editType><file>community/community-war/src/main/java/org/silverpeas/components/community/web/CommunityMembershipResource.java</file></path><path><editType>edit</editType><file>pom.xml</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path><path><editType>edit</editType><file>components-restapi/pom.xml</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/CommonResponsesFilter.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>questionReply/questionReply-war/src/main/java/org/silverpeas/components/questionreply/web/ReplyResource.java</file></path><path><editType>edit</editType><file>quickinfo/quickinfo-war/src/main/java/org/silverpeas/components/quickinfo/web/NewsResource.java</file></path><path><editType>edit</editType><file>suggestionBox/suggestionBox-war/src/main/java/org/silverpeas/components/suggestionbox/web/SuggestionBoxResource.java</file></path><path><editType>delete</editType><file>components-restapi/src/main/java/org/silverpeas/components/restapi/JaxbAwareModelResolver.java</file></path><path><editType>edit</editType><file>gallery/gallery-war/src/main/java/org/silverpeas/components/gallery/web/GalleryResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components-restapi/pom.xml</affectedPath><commitId>9d3490bf7cd64723cdac38d15472d03679bb8950</commitId><timestamp>1790597554000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Opt in the stripping of the Maven site

The strip-maven-site execution of the parent POM is now skipped by default: it
used to apply to every project inheriting from that POM and wiped out the Maven
site such a project publishes. This module publishes the documentation of the
REST API and nothing else, so it asks for the execution by setting
strip.maven.site.skip to false.
</comment><date>2026-09-28 14:12:34 +0200</date><id>9d3490bf7cd64723cdac38d15472d03679bb8950</id><msg>Opt in the stripping of the Maven site</msg><path><editType>edit</editType><file>components-restapi/pom.xml</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</affectedPath><affectedPath>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</affectedPath><commitId>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1460

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The title and the body of a forum message were printed raw by JSP scriptlets on
the thread page, so any script posted by a user of the forum was run in the
browser of every user reading it.

The title is now HTML encoded on output, as the other JSPs of the component
already do through WebEncodeHelper. Two other raw outputs of the title, which
the report doesn't mention, are encoded as well: the one of modifyMessage.jsp,
where the title lands in the value attribute of an input and is hence
exploitable by escaping that attribute, and the one of editMessageKeywords.jsp.

The body is sanitized by the applySanitizeForRenderingDirective directive
introduced in Silverpeas-Core for the vulnerability #1459, which drops what can
act on the visitor's browser while keeping the content as it is.

Note the report also states the title pollutes the title element of the page.
It does appear there, but viewMessage.jsp already prints it through a c:out tag,
so it is encoded and isn't a vector.

Co-Authored-By: Claude Opus 5 (1M context) &lt;noreply@anthropic.com&gt;
(cherry picked from commit ea479b045468c5015e93e8b6c0924b919f8e4f32)
</comment><date>2026-09-28 14:43:22 +0200</date><id>3b4d732f0a1b27af91286d6a8bf01e77d8d3bde2</id><msg>Fix vulnerability #1460</msg><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/viewMessage.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/editMessageKeywords.jsp</file></path><path><editType>edit</editType><file>forums/forums-war/src/main/webapp/forums/jsp/modifyMessage.jsp</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</affectedPath><commitId>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1461

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The image of a watermark is an instance parameter any manager of the space
holding the gallery can set, and the server requests it as it is, at each media
creation. It could hence be pointed at a service the server keeps for itself.

Such an URL is now verified before being requested: only the HTTP and HTTPS
schemes are handled, and the host must resolve to neither a loopback nor a
link-local address, so that neither the services bound to the server itself nor
the metadata endpoint of a cloud provider can be reached. Every address the host
resolves to is verified, otherwise a host resolving to a forbidden address
beside an allowed one would go through.

The addresses of the private networks of an organization remain reachable on
purpose: they are where the internal resources of an intranet legitimately live,
and no address range can tell them from the internal services one would rather
protect. Only an explicit list of allowed hosts could, which is left to a
further decision.

The request is besides given a timeout and its response is no longer copied
without any bound, both being able to exhaust the resources of the server, and
the redirections are no longer followed as they would escape the verification
above.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 83864c0f72b6c5f62a1afdf2cb420f8b62840f20)
</comment><date>2026-09-28 14:43:22 +0200</date><id>b0d04438a605a666ee748f7c6ca310fef0ff6a4a</id><msg>Fix vulnerability #1461</msg><path><editType>add</editType><file>gallery/gallery-library/src/test/java/org/silverpeas/components/gallery/WatermarkTest.java</file></path><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>03b14dd2f030f634a99944c3272b31500811242f</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1462 and secure the other writings of the newsletter

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Publishing an issue of a newsletter changes its state, stamps its publication
date, notifies the subscribers and mails the external ones. It was requested by
a GET, and the synchronizer token is required on a GET only when its URL holds
one of a few keywords, which ValidateParution holds none of. Any logged user
lured into a cross-site visit was hence publishing the issue as themselves.

The publication is now submitted by POST, on which the token is required
whatever the URL, through the formRequest facility which stamps it.

Moreover the endpoint had no role check at all, so any reader of the newsletter
was able to publish an issue and to trigger the mailing, with no luring needed.
Only its publishers and its managers can do so now.

Three other writings, which the report doesn't mention, were exposed the same
way and are secured likewise:
- resetting the content of an issue with its template, which overwrites the
  content being written;
- mailing an issue to oneself and to the managers, which sends the content of an
  issue not published yet and was hence a way for any reader to get a draft.

As EditContent also serves the edition itself, a mere navigation which remains a
GET, the reset is explicitly refused when it isn't requested by POST: submitting
it by POST would otherwise protect nothing, the previous URL remaining
requestable.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 4bd5e04d16207d889d2b271eed87fa1962fa8ab5)
</comment><date>2026-09-28 14:43:22 +0200</date><id>03b14dd2f030f634a99944c3272b31500811242f</id><msg>Fix vulnerability #1462 and secure the other writings of the newsletter</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/headerLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/previewLetter.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</affectedPath><affectedPath>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</affectedPath><commitId>0b6076009ffb133c105e4861267e1cda62176d78</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerabilities #1463

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

The operations on the issues themselves were exposed the same way and are
secured likewise: creating and modifying an issue, and modifying the headers of
the newsletter, were requestable by a GET although their forms are submitted by
POST, the router not caring about the method.

None of the operations of this router had any role check, so any reader was able
to write the content of an issue, to modify the headers of the newsletter, to
delete issues and to read the ones being written. They are now reserved to the
publishers and to the managers, but for the ones on the template and the
deletion of several issues at once, reserved to the managers.

Reading the inlined CSS rendering of an issue is how the readers get it from the
list, so the criterion there isn't the role but the issue itself: it is refused
to them as long as it isn't published.

(cherry picked from commit e455edb9286b8b429cbb7fc1c54de6f75ead8dfd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>0b6076009ffb133c105e4861267e1cda62176d78</id><msg>Fix vulnerabilities #1463</msg><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterUser.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/webapp/infoLetter/jsp/listLetterAdmin.jsp</file></path><path><editType>edit</editType><file>infoLetter/infoLetter-war/src/main/java/org/silverpeas/components/infoletter/servlets/InfoLetterRequestRouter.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #1464

(GitHub issue of Silverpeas-Core, reported against 6.4.6)

Loading publications into the clipboard and pasting them under another topic
were requestable by a GET, so any logged user lured into a cross-site visit was
moving publications as themselves.

The AJAX servlet of kmelia answers the GET as the POST, and none of its URLs
holds any of the keywords making the synchronizer token required on a GET. So
none of its operations was protected, including the deletion of publications
which the report takes as protected: its URL does hold the delete keyword, but
the rule applied to this servlet requires in addition the path to hold /jsp/,
which the path of a servlet doesn't.

The operations only reading something are now listed apart, every other one
being taken as writing something so that adding an operation doesn't expose it
by mistake, and a writing operation requested by a GET is refused. That refusal
is performed before the processing, whose catch-all would swallow it.

The user interface already submitted by POST the operations the report points
at, as well as the deletion, the copy and the move of publications: what made
the attack possible is the servlet accepting the GET. Three operations were
still requested by a GET and are now submitted by POST: sorting the topics,
emptying the trash from the basket, and binding a publication to another one.

(cherry picked from commit 9d1faf9ba0366440299b0907b00a0ab5397f5bdd)
</comment><date>2026-09-28 14:43:22 +0200</date><id>dbb4f8e6ae7b2f71c500e2457c9a7cb299fa12dc</id><msg>Fix vulnerability #1464</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/orderTopics.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/basket.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/webapp/kmelia/jsp/publicationLinksManager.jsp</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/ajax/AjaxOperation.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</affectedPath><affectedPath>kmelia/kmelia-war/pom.xml</affectedPath><affectedPath>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</affectedPath><commitId>f371b6452d9360af47926ebccceba45e05d252ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Fix vulnerability #939

(GitHub issue of Silverpeas-Components, reported against 6.4.6)

Updating a publication was granted against the component instance referred by
the URL, whereas the publication to update was entirely defined by the request
body, which carries both its identifier and its component instance. Any user
could hence rewrite the metadata of any publication of the platform by referring
it in the body, the identifiers being enumerable.

The publication is now refused when it doesn't belong to the instance the
authorization has been checked against. Note the report states a WRITER role is
required: it is not, the authorization of the REST framework only validating the
access to the instance whatever the role played in it, so the exposure was wider
than reported. Writing a publication, be it created or updated, now requires
that role indeed.

KmeliaResourceTest covers the checks. The war had no test at all, hence the
test dependency added to its POM.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit 1d8ec7ee0a903b041ffac54b022319ff099b12ce)
</comment><date>2026-09-28 14:43:22 +0200</date><id>f371b6452d9360af47926ebccceba45e05d252ca</id><msg>Fix vulnerability #939</msg><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/web/KmeliaResource.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/pom.xml</file></path><path><editType>add</editType><file>kmelia/kmelia-war/src/test/java/org/silverpeas/components/kmelia/web/KmeliaResourceTest.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</affectedPath><affectedPath>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</affectedPath><commitId>bb7f36a57f96d33b8bd92d826056770e3c14e04c</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Reserve the management of the delegated news to the managers

Modifying and deleting the delegated news is reserved to the managers of the
application, as its user interface applies on its side. The REST service was
granted against a mere access to the component instance, whatever the role
played in it, so any of its users was able to reorder and to delete them by
requesting it directly.

Found while auditing the other REST resources against the flaw reported by the
issue #939 of this repository.

ListDelegatedNewsResourceTest covers the check.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
(cherry picked from commit e4271c328772c51f400cbeab7eeb6f7fb2876721)
</comment><date>2026-09-28 14:43:22 +0200</date><id>bb7f36a57f96d33b8bd92d826056770e3c14e04c</id><msg>Reserve the management of the delegated news to the managers</msg><path><editType>add</editType><file>delegatednews/delegatednews-war/src/test/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResourceTest.java</file></path><path><editType>edit</editType><file>delegatednews/delegatednews-war/src/main/java/org/silverpeas/components/delegatednews/web/ListDelegatedNewsResource.java</file></path></item><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</affectedPath><affectedPath>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</affectedPath><commitId>eca5145d6d01f77adce83ef714742073585675ca</commitId><timestamp>1790599402000</timestamp><author><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></author><authorEmail>miguel.moquillon@gmail.com</authorEmail><comment>Take into account sonarcloud feedback
</comment><date>2026-09-28 14:43:22 +0200</date><id>eca5145d6d01f77adce83ef714742073585675ca</id><msg>Take into account sonarcloud feedback</msg><path><editType>edit</editType><file>gallery/gallery-library/src/main/java/org/silverpeas/components/gallery/Watermark.java</file></path><path><editType>edit</editType><file>kmelia/kmelia-war/src/main/java/org/silverpeas/components/kmelia/servlets/AjaxServlet.java</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><previousBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></previousBuild></lastSuccessfulBuild><lastUnsuccessfulBuild _class='org.jenkinsci.plugins.workflow.job.WorkflowRun'><action _class='hudson.model.ParametersAction'><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></parameter><parameter _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></parameter></action><action _class='hudson.model.CauseAction'><cause _class='hudson.model.Cause$UserIdCause'><shortDescription>Démarré par l'utilisateur Miguel Moquillon</shortDescription><userId>mmoquillon</userId><userName>Miguel Moquillon</userName></cause></action><action _class='org.jenkinsci.plugins.workflow.libs.LibrariesAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.cps.EnvActionImpl'></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><branch><SHA1>56f5661a313b8828cac18f92b68f2f116fbd2cc2</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Jenkins-Pipelines.git</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginsonarqube _class='hudson.plugins.git.util.Build'><buildNumber>261</buildNumber><marked><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></marked><revision><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><branch><SHA1>96a3a41e61a0a59a294dd74fce10884c559e77f4</SHA1><name>refs/remotes/origin/sonarqube</name></branch></revision></refsremotesoriginsonarqube><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><branch><SHA1>969e2118e87aad06e5a036b5cec76d30c7e30867</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Core</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><branch><SHA1>d68cf30b72373be33de0696997667755117f3fb6</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Components</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><branch><SHA1>3371d6a08cdacadc5573189be43a2d6beaff5437</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Looks</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><branch><SHA1>ba454f4f93b74cf8e576d2a33606dc23d5431702</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Setup</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><branch><SHA1>0c4cdcb02f8e0a964f759187b9cfdfa8870d806b</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Distribution</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginmaster _class='hudson.plugins.git.util.Build'><buildNumber>1162</buildNumber><marked><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></marked><revision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></revision></refsremotesoriginmaster></buildsByBranchName><lastBuiltRevision><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><branch><SHA1>7b2e624fce9db2e795b6e3d50485622b4024aa16</SHA1><name>refs/remotes/origin/master</name></branch></lastBuiltRevision><remoteUrl>https://github.com/Silverpeas/Silverpeas-Assembly</remoteUrl><scmName></scmName></action><action></action><action></action><action></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'></action><action _class='org.jenkinsci.plugins.pipeline.modeldefinition.actions.RestartDeclarativePipelineAction'></action><action></action><action _class='org.jenkinsci.plugins.workflow.job.views.FlowGraphAction'></action><action></action><action></action><building>false</building><displayName>#1162</displayName><duration>3135500</duration><estimatedDuration>10550775</estimatedDuration><fullDisplayName>Silverpeas_Master_AutoDeploy #1162</fullDisplayName><id>1162</id><keepLog>false</keepLog><number>1162</number><queueId>63310</queueId><result>FAILURE</result><timestamp>1790584035065</timestamp><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1162/</url><culprit><absoluteUrl>https://integration.silverpeas.org/jenkins/user/mmoquillon</absoluteUrl><fullName>Miguel Moquillon</fullName></culprit><inProgress>false</inProgress><nextBuild><number>1163</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1163/</url></nextBuild><previousBuild><number>1161</number><url>https://integration.silverpeas.org/jenkins/job/Silverpeas_Master_AutoDeploy/1161/</url></previousBuild></lastUnsuccessfulBuild><nextBuildNumber>1165</nextBuildNumber><property _class='hudson.model.ParametersDefinitionProperty'><parameterDefinition _class='hudson.model.BooleanParameterDefinition'><defaultParameterValue _class='hudson.model.BooleanParameterValue'><name>SKIP_TEST</name><value>false</value></defaultParameterValue><description>Flag indicating if the execution of the tests should be skipped</description><name>SKIP_TEST</name><type>BooleanParameterDefinition</type></parameterDefinition><parameterDefinition _class='hudson.model.BooleanParameterDefinition'><defaultParameterValue _class='hudson.model.BooleanParameterValue'><name>SKIP_QUALITY</name><value>false</value></defaultParameterValue><description>Indicates whether the code quality analysis have to be skipped</description><name>SKIP_QUALITY</name><type>BooleanParameterDefinition</type></parameterDefinition></property><property _class='hudson.plugins.copyartifact.CopyArtifactPermissionProperty'></property><property _class='jenkins.model.BuildDiscarderProperty'></property><property _class='org.jenkinsci.plugins.workflow.job.properties.PipelineTriggersJobProperty'></property><concurrentBuild>true</concurrentBuild><disabled>false</disabled><inQueue>false</inQueue><resumeBlocked>false</resumeBlocked></workflowJob>