jenkinsci / jenkinsci/script-security-plugin
[JENKINS-75349] Enhance Whitelist checking to inspect invokeMethod arguments
- Dominant language
- Java
- Stars
- 76
- Forks
- 181
- Avg merge
- 14h 55m
- Merged PRs (30d)
- 3
Description
Currently the special groovy invokeMethod method is either whitelisted as a whole or rejected as a whole.
This could be enhanced to check if either invokeMethod is permitted or the method invokeMethod is calling is permitted. If nether is permitted then the UI approve list could add both methods.
This enhancement would allow for selective invokeMethod use which is required for things like proxying or the groovy @Delegate annotation.
---
Originally reported by mrichar2, imported from: Enhance Whitelist checking to inspect invokeMethod arguments
Raw content of original issue
Currently the special groovy invokeMethod method is either whitelisted as a whole or rejected as a whole.
This could be enhanced to check if either invokeMethod is permitted or the method invokeMethod is calling is permitted. If nether is permitted then the UI approve list could add both methods.
This enhancement would allow for selective invokeMethod use which is required for things like proxying or the groovy @Delegate annotation.
Contributor guide
Assessment
This issue has not been assessed yet.