[OWASP-ESAPI] ESAPI 1.4 released!

Kevin Fealey kfealz at gmail.com
Mon Nov 3 17:03:18 EST 2008

ESAPI 1.4 has been
The links to earlier versions of the ESAPI have been deprecated on
Code.  They are still accessible, but will not display by default.  Here are
some of the changes in 1.4:

   - Updated Javadocs for interfaces to describe what reference
   implementations should accomplish.
   - Fixed tags in Javadocs so parameter names, etc. should be correct.
   - Removed all references to interfaces that no longer exist.
   - Added Multi-platform support for ESAPI test cases.  They have been
   tested for compatibility with MacOS X, Linux, Solaris, and Windows Vista.
   - Updated Javascript codec to better follow the spec.
   - Added session tracking to User to track multiple sessions.
   - Updated Logger to read logging level out of ESAPI.properties.
   - Edited Logger to output to a file specified in the security
   - Enhanced log output format.
   - Added methods to FileBasedAccessController to view data as objects,
   rather than Strings.

Our goal for this release was to enhance functionality and usability, ie.
make it easier for developers to use the API.  We feel that by clarifying
many topics in the Javadocs, it should be much easier to get started with

We've seen a solid response from people starting to use the ESAPI, and we're
getting a lot of questions about how some things work.  I'm going to try to
add new content to the Wiki <https://www.owasp.org/index.php/ESAPI> weekly
to address most of the questions, so please check back

-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://lists.owasp.org/pipermail/owasp-esapi/attachments/20081103/f8a6a9d8/attachment.html 

More information about the OWASP-ESAPI mailing list