Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wow, that’s a scary read…

No consideration, no discussion, no security analysis, just “JDNI is cool, can I hav plz? Ofc!”

Did none of these people consider what JDNI is designed to do?

Did none of these people consider what side-effects are appropriate within a logging library?



Yes... but... realize that log4j2 was in beta releases at the time, being maintained by one developer as part of a "I want to redesign how it works".

As an open source developer working on a project that hadn't even been formally released, I'd be quite pleased to have someone else contributing the features that they found useful back upstream in an effort to make it a better project.

Yes, this is what jndi is supposed to do. Was it done as best as it could be? Probably not. But it isn't something that's only in log4j2

http://logback.qos.ch/manual/loggingSeparation.html#ContextJ...

https://dennis-xlc.gitbooks.io/the-logback-manual/content/en...

But I'm not going to fault a solo developer of some beta software in the world of 2013 for not rejecting a patch because every angle wasn't thought out.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: