...
Wiki Markup |
---|
\[[Chan 99|AA. Java References#Chan 99]\] java.lang.reflect AccessibleObject \[[SCG 07|AA. Java References#SCG 07]\] Guideline 6-4 Be aware of standard APIs that perform Java language access checks against the immediate caller |
...
SEC33SEC02-J. Do not expose standard APIs that use the immediate caller's class loader instance may bypass Security Manager checks to untrusted code 01. Platform Security (SEC) SEC06SEC04-J. Assume that all Java clients can be reverse engineered, monitored, and modifiedDo not rely on the default automatic signature verification provided by URLClassLoader and java.util.jar