Interface ExpressionSecurityValidator


  • public interface ExpressionSecurityValidator
    Service interface for EL expression security validation. This service can be used by other bundles to validate EL expressions for security issues.

    The validation process includes checking for:

    • Configurable denylist patterns (checked first)
    • Static allowlist for AEM solution expressions
    • Customer configurable allowlist
    • Arithmetic expressions that might indicate injection
    • Dangerous class access patterns
    Since:
    5.10.15
    • Method Detail

      • validateExpression

        void validateExpression​(java.lang.String expression)
                         throws javax.el.ELException
        Validates an EL expression for security issues.
        Parameters:
        expression - The EL expression to validate
        Throws:
        javax.el.ELException - if the expression contains dangerous patterns
      • sanitizeExpression

        java.lang.String sanitizeExpression​(java.lang.String expression)
        Sanitizes an EL expression by removing dangerous content.
        Parameters:
        expression - The EL expression to sanitize
        Returns:
        A safe version of the expression