Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8074391

imperfect jnlp file brings up misleading security dialog 'Application Blocked by Java Security'

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: P3
    • Resolution: Won't Fix
    • Affects Version/s: 7u76, 8u40
    • Fix Version/s: 9
    • Component/s: deploy
    • Subcomponent:
    • CPU:
      x86
    • OS:
      windows_vista

      Description


      jnlp file contains a typo. The <description> tag is imperfect, missing closing '>'.
      As a result, the security dialog 'Application Blocked by Java Security' is presented.
      This is confusing and misleading, as the application implements the manifest attributes
      and is signed with an official certificate.

      Here is the imperfect jnlp file:

      # more simple-defective.jnlp
      <?xml version="1.0" encoding="utf-8"?>
      <jnlp codebase = "http://xxx:8880/simpleNoGUI-defective" href="simple-defective.jnlp" >
        <information>
              <title>Java Web Start - Simple</title>
              <vendor>Simple Demo w/o GUI </vendor>
              <descriptionWebStart Simple App</description>
        </information>

        <security>
              <all-permissions/>
        </security>

        <resources>
              <j2se version="1.8+" />
        </resources>
        <resources>
              <jar href="simple.jar" />
        </resources>

        <application-desc main-class="webstart.Simple" >
        </application-desc>

      </jnlp>

        Attachments

        1. 20150304-8u40-security-dialog.png
          20150304-8u40-security-dialog.png
          130 kB
        2. 20150304-8u40-works.png
          20150304-8u40-works.png
          120 kB
        3. 20150306-8u40-Blocked-Dailog-app2.png
          20150306-8u40-Blocked-Dailog-app2.png
          124 kB
        4. 20150306-8u40-Blocked-Dialog-app1.png
          20150306-8u40-Blocked-Dialog-app1.png
          126 kB
        5. 20150306-8u40-show-signing-certificate.png
          20150306-8u40-show-signing-certificate.png
          145 kB
        6. 20150306-8u40-simple-starts-fine.png
          20150306-8u40-simple-starts-fine.png
          120 kB
        7. 20150309-8u40-launch-defective.png
          20150309-8u40-launch-defective.png
          63 kB
        8. jnlp.jar
          6 kB
        9. jnlp.jar
          6 kB
        10. launch.jnlp
          0.6 kB
        11. launch.jnlp
          0.6 kB
        12. launch1.jnlp
          0.6 kB
        13. launch1.jnlp
          0.6 kB

          Activity

            People

            • Assignee:
              stayer Kirill Kirichenko (Inactive)
              Reporter:
              thlenz Thomas Lenz (Inactive)
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: