From 8a2d52e17f3e40149e65b61016bdc335ca199d15 Mon Sep 17 00:00:00 2001 From: Simon Tzanakis Date: Fri, 11 Oct 2024 11:15:23 +0200 Subject: [PATCH] MET-6211 Process review --- .../rest/controller/AuthenticationController.java | 2 +- .../main/java/eu/europeana/metis/utils/CommonStringValues.java | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/metis-authentication/metis-authentication-rest/src/main/java/eu/europeana/metis/authentication/rest/controller/AuthenticationController.java b/metis-authentication/metis-authentication-rest/src/main/java/eu/europeana/metis/authentication/rest/controller/AuthenticationController.java index 60f6201e2..98a201954 100644 --- a/metis-authentication/metis-authentication-rest/src/main/java/eu/europeana/metis/authentication/rest/controller/AuthenticationController.java +++ b/metis-authentication/metis-authentication-rest/src/main/java/eu/europeana/metis/authentication/rest/controller/AuthenticationController.java @@ -207,7 +207,7 @@ public void updateUserToMakeAdmin(@RequestHeader("Authorization") String authori if (emailParameter == null || StringUtils.isBlank(emailParameter.getEmail())) { throw new BadContentException("userEmailToMakeAdmin is empty"); } - String accessToken = authenticationService.validateAuthorizationHeaderWithAccessToken(authorization); + final String accessToken = authenticationService.validateAuthorizationHeaderWithAccessToken(authorization); if (!authenticationService.isUserAdmin(accessToken)) { throw new UserUnauthorizedException(ACTION_NOT_ALLOWED_FOR_USER); } diff --git a/metis-common/metis-common-utils/src/main/java/eu/europeana/metis/utils/CommonStringValues.java b/metis-common/metis-common-utils/src/main/java/eu/europeana/metis/utils/CommonStringValues.java index 8950c50b6..d618079ce 100644 --- a/metis-common/metis-common-utils/src/main/java/eu/europeana/metis/utils/CommonStringValues.java +++ b/metis-common/metis-common-utils/src/main/java/eu/europeana/metis/utils/CommonStringValues.java @@ -31,7 +31,7 @@ private CommonStringValues() { /** * Sanitized input value from Logging injection attacks(javasecurity:S5145). - *

Replaces CR and LF characters with a safe value e.g. '_'.

+ *

Replaces CR and LF characters with a safe value e.g. ""(empty string).

* * @param input the input * @return the sanitized input, safe for logging