lmajano
05/14/2025, 9:43 AMnimitsharma
05/14/2025, 10:50 AMDave Merrill
05/14/2025, 11:51 AMRodney
05/14/2025, 11:53 AMRodney
05/14/2025, 11:55 AMDave Merrill
05/14/2025, 12:03 PMRodney
05/14/2025, 12:11 PMrodel30
05/14/2025, 3:21 PM-Dcoldfusion.runtime.remotemethod.matchArguments=false. The issue I have with it is that even when the function isn't being called remotely it enforces the argument matching.Dave Merrill
05/14/2025, 3:34 PMfunction validateOneRow(required struct stValues)
Where stValues is typically the whole form scope, maybe with other stuff added, removed, or changed.Dave Merrill
05/14/2025, 3:35 PMrodel30
05/14/2025, 3:36 PMDave Merrill
05/14/2025, 4:15 PMDave Merrill
05/14/2025, 4:16 PMlmajano
05/15/2025, 8:08 AMlmajano
05/15/2025, 8:08 AMlmajano
05/15/2025, 8:08 AMlmajano
05/15/2025, 8:09 AMlmajano
05/15/2025, 8:10 AMlmajano
05/15/2025, 8:10 AMlmajano
05/15/2025, 8:11 AMThis change ensures stricter method integrity and a better debugging experienceBK BK
05/15/2025, 8:45 AM-Dcoldfusion.runtime.remotemethod.matchArguments the cause of the issue?BK BK
05/15/2025, 9:00 AMMichael Owen
05/16/2025, 4:18 PMfalse .
I would argue that generating an error gives an attacker a method to discover the contours of your remote methods. Silent removal of such things is our policy. To be clear, not publishing or ":hiding" special method arguments is not secure; but your app should be handling that anyway.
What if a network appliance or service between the browser and ColdFusion adds a query parameter. Would you have to strip it in Application.cfc ?
+1 dynamic arguments.
There is a jvm arg but again defaulting to false would have made this less painful.Dave Merrill
05/16/2025, 5:47 PMlmajano
05/16/2025, 8:54 PMlmajano
05/16/2025, 8:54 PMlmajano
05/16/2025, 8:55 PMlmajano
05/16/2025, 8:56 PM