Improved: Better secure "openSourceFile" request-map (OFBIZ-13316)
See OFBIZ-12018
diff --git a/ecommerce/webapp/ecommerce/WEB-INF/controller.xml b/ecommerce/webapp/ecommerce/WEB-INF/controller.xml
index 1992d9d..3d7fa70 100644
--- a/ecommerce/webapp/ecommerce/WEB-INF/controller.xml
+++ b/ecommerce/webapp/ecommerce/WEB-INF/controller.xml
@@ -185,7 +185,7 @@
<!-- open the corresponding FTL file with IDE when the named border is clicked from browser -->
<request-map uri="openSourceFile">
- <security https="false" auth="false"/>
+ <security https="true" auth="true"/>
<event type="java" path="org.apache.ofbiz.common.CommonEvents" invoke="openSourceFile"/>
<response name="success" type="none" />
<response name="error" type="none" />