SPC020210: Do not add PageParserPaths to web.config

PageParserPaths can be used to enable inline code in ASPX pages which is not allowed.

TypeName: DoNotAddPageParserPathToWebConfig
CheckId: SPC020210
Severity: CriticalWarning
Type: AssemblyFileReference
Resolution

Do not add PageParserPaths to web.config via SPWebConfigModification to enable inline code in ASPX pages.

Remarks

The rule can only check the appearance of 'SPWebConfigModification' and the string 'PageParserPaths' in the same class. This can lead to false positive results.

Links

comments powered by Disqus