FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Properties and properties files that are required, even if esapi logging is not used · Issue #742 · ESAPI/esapi-java-legacy · GitHub

Repository navigation

Properties and properties files that are required, even if esapi logging is not used #742

Description

Our project uses the esapi library, but only for the encoding tools. We don't use esapi logging. I recently upgraded from v2.1.0.1 to 2.5.0.0, and I noticed that now it requires this "esapi-java-logging.properties" file, even though we don't use esapi logging. At this point, it appears that just creating an empty file works, but it's just a little weird that we have to do this. I also noticed that I had to add several new properties to ESAPI.properties, again, specific to esapi logging, which we don't use. If I don't set those properties, a fatal error occurs.

Properties should have reasonable default values, and it doesn't make sense to require a properties file to exist if it's going to be empty.

Activity

  1. jeremiahjstacey commented on Sep 11, 2022

    Collaborator

    Although your project may not call the ESAPI logging API directly, it is still referenced at runtime and is required by the library components you are using. ESAPI Logging is a transitive requirement of any other feature provided by the library.

    In Short: ESAPI components use the ESAPI logging configuration.

    My current understanding is that this is presently expected behavior, which is why there has been a great deal of documentation generated around the logging configuration requirements and changes in the last few releases.

  2. kwwall commented on Sep 11, 2022

    Contributor
  3. davidmichaelkarr commented on Sep 11, 2022

    Author

    Ok, well, that's a very good point. I'll examine what we're using from ESAPI, I do believe it's only the encoder, and examine a transition to the OWASP encoder.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL