Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-116075

Add support for a template engine with restricted capabilities so that it can be used in multi-customer installations (X)



      Currently Liferay provides support for several template engines, the most popular of which is Freemarker. However freemarker is quite powerful, allowing for the execution of Java code and taglibs. This makes it unfeasible for installations that are shared for several unrelated end customers, since the code introduced in a freemarker template could impact the system and thus all customers.

      The goal of this Epic is to find a solution to this by adding support for a template engine that meets more strict scalability, performance, and security requirements that ensure is is safe to use them in multi-customer environments.

      An alternative to adding support for a new template language would be to implement stricter restrictions for the execution of freemarker code and provide a configuration option to choose whether to run them in strict mode or not.




            • Votes:
              1 Vote for this issue
              0 Start watching this issue


              • Created:


                Version Package