Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request from patched fixes 4 issues.
Fixed vulnerabilities and improved security of login and authentication mechanism.
Fixed object deserialization vulnerability by hashing the content of the serialized object and allowing only authorized objects to be deserialized. Set the 'HttpOnly' and 'secure' flags for cookies to improve security.Fixed vulnerability in SearchController by validating user input before evaluating in Spring Expression
The code has been modified to validate the user input before evaluating it in the Spring Expression. This fix prevents the possibility of a malicious input causing an adverse effect on the system.Fix hardcoded AWS credentials
Replaced hardcoded AWS Access Key ID and Secret Key with environment variables AWS_ACCESS_KEY_ID and AWS_SECRET_KEY.