p.s. I get your point that dynamically allowed fields hasn't been a jira. I'm not saying that spring should have thought of (though that would have been nice) but this would have been solved if spring already provided a security filter like HDIV. Obviously this thread is about the whole OWASP - I just hijacked it with another example of why we need it - of which dynamically allowed fields are perhaps the least obvious reason, but still important if spring offers a security solution that allows the approach I have implemented.


Reply With Quote
