Skip to content

Conversation

@vwagh-dev
Copy link
Owner

Plugin Development L3: Adding the configuration section with credentials

System.out.println("Password: " + password);
}

public FormValidation doCheckName(@QueryParameter String name) {

Check warning

Code scanning / Jenkins Security Scan

Stapler: Missing permission check

Potential missing permission check in OnboardingPluginGlobalConfiguration#doCheckName
System.out.println("Password: " + password);
}

public FormValidation doCheckName(@QueryParameter String name) {

Check warning

Code scanning / Jenkins Security Scan

Stapler: Missing POST/RequirePOST annotation

Potential CSRF vulnerability: If OnboardingPluginGlobalConfiguration#doCheckName connects to user-specified URLs, modifies state, or is expensive to run, it should be annotated with @POST or @RequirePOST
return FormValidation.ok();
}

public FormValidation doCheckPwd(@QueryParameter String pwd) {

Check warning

Code scanning / Jenkins Security Scan

Stapler: Missing permission check

Potential missing permission check in OnboardingPluginGlobalConfiguration#doCheckPwd
return FormValidation.ok();
}

public FormValidation doCheckUsername(@QueryParameter String username) {

Check warning

Code scanning / Jenkins Security Scan

Stapler: Missing permission check

Potential missing permission check in OnboardingPluginGlobalConfiguration#doCheckUsername
return FormValidation.ok();
}

public FormValidation doCheckPwd(@QueryParameter String pwd) {

Check warning

Code scanning / Jenkins Security Scan

Stapler: Missing POST/RequirePOST annotation

Potential CSRF vulnerability: If OnboardingPluginGlobalConfiguration#doCheckPwd connects to user-specified URLs, modifies state, or is expensive to run, it should be annotated with @POST or @RequirePOST
return FormValidation.ok();
}

public FormValidation doCheckUsername(@QueryParameter String username) {

Check warning

Code scanning / Jenkins Security Scan

Stapler: Missing POST/RequirePOST annotation

Potential CSRF vulnerability: If OnboardingPluginGlobalConfiguration#doCheckUsername connects to user-specified URLs, modifies state, or is expensive to run, it should be annotated with @POST or @RequirePOST
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants