[Owasp-esapi-c++] Boost::Test nil_t warnings

Kevin W. Wall kevin.w.wall at gmail.com
Mon Aug 29 10:15:44 EDT 2011


On Mon, Aug 29, 2011 at 9:37 AM, Daniel Amodio
<dan.amodio at aspectsecurity.com> wrote:
> Here is the list that David made
>
>> Bimap

Bitmap ???

>> DateTime
>> Filesystem?
>> Program Options
>> Property Map
>> Regex/Xpressive
>> System
>> Test
>> Tokenizer?

OK, I think this list is reasonable. Note that some of the parts
mentioned (e.g., "Program Options", possibly "System") might
not have a corresponding security control with ESAPI 2.0 for JavaEE.

Of these things, at some point, I think we are definitely going to need
to use something to support file system (e.g., AccessController),
regex (used throughout the Validators), and Property Map (e.g.,
for SecurityConfiguration or whatever we use to support the
ESAPI for C++ properties).

I just think we haven't gotten enough into most of those security
cotnrols yet though where Boost might become useful.

-kevin
-- 
Blog: http://off-the-wall-security.blogspot.com/
"The most likely way for the world to be destroyed, most experts agree,
is by accident. That's where we come in; we're computer professionals.
We *cause* accidents."        -- Nathaniel Borenstein


More information about the Owasp-esapi-c++ mailing list