Platform Explorer / Nuxeo Platform LTS 2017 9.10

Component org.nuxeo.ecm.automation.server.bindings

Contributions

XML Source

<?xml version="1.0"?>
<component name="org.nuxeo.ecm.automation.server.bindings"
  version="1.0">

  <extension target="org.nuxeo.ecm.automation.server.AutomationServer"
    point="bindings">
    <!-- don't allow GET of arbitrary URLs on the server -->
    <binding name="Blob.CreateFromURL">
      <administrator>true</administrator>
    </binding>
    <!-- don't allow POST of arbitrary URLs on the server -->
    <binding name="Blob.Post">
      <administrator>true</administrator>
    </binding>
    <!-- don't allow write of arbitrary files on the server -->
    <binding name="Blob.ExportToFS">
      <administrator>true</administrator>
    </binding>
    <!-- don't allow arbitrary email sending on the server -->
    <binding name="Document.Mail">
      <administrator>true</administrator>
    </binding>

    <!-- protect access to directories -->
    <binding name="Directory.Entries">
      <administrator>true</administrator>
    </binding>
    <!-- protect arbitrary script execution -->
    <binding name="RunInputScript">
      <administrator>true</administrator>
    </binding>
    <binding name="RunScript">
      <administrator>true</administrator>
    </binding>
    <!-- protect counter access -->
    <binding name="Counters.GET">
      <administrator>true</administrator>
    </binding>
  </extension>

</component>