Skip to content
#

vaadin

Here are 679 public repositories matching this topic...

FSchliephacke
FSchliephacke commented Oct 30, 2018

Vaadin Framework version: 8, all versions

There is a major error in the class com.vaadin.server.VaadinSession (and possibly other classes too, if this is some kind of cargo cult programming in the Vaadin team)

Most public methods in the class use assertions to "check" if the session has the lock. This is fundamentally wrong. Assertions are the wrong tool to check preconditions in public meth

pleku
pleku commented Apr 1, 2021

The API is problematic as users keep using it to workaround problems in their layouting when the grid is not expanding (see for example vaadin/flow#10511) without realizing that it will make all rows shown and in the worst case fetched from the backend. No, they are not reading the javadocs either https://github.com/vaadin/flow-components/blob/master/vaadin-grid-flow-parent/vaadin-grid-flow/src/ma

fluorumlabs
fluorumlabs commented Oct 29, 2020

Warning: Non-constant format string in String.format() (CWE-134)

The software uses a function that accepts a format string as an argument,
but the format string originates from an external source.

When an attacker can modify an externally-controlled format string, this
can lead to denial of service or data representation problems.

I

Improve this page

Add a description, image, and links to the vaadin topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the vaadin topic, visit your repo's landing page and select "manage topics."

Learn more