in src/main/java/org/apache/sling/jcr/base/internal/LoginAdminWhitelist.java [136:153]
private ConfigurationState(final LoginAdminWhitelistConfiguration config) {
final String regexp = config.whitelist_bundles_regexp();
if(regexp.trim().length() > 0) {
whitelistRegexp = Pattern.compile(regexp);
LOG.warn("A 'whitelist.bundles.regexp' is configured, this is NOT RECOMMENDED for production: {}",
whitelistRegexp);
} else {
whitelistRegexp = null;
}
bypassWhitelist = config.whitelist_bypass();
if(bypassWhitelist) {
LOG.info("bypassWhitelist=true, whitelisted BSNs=<ALL>");
LOG.warn("All bundles are allowed to use loginAdministrative due to the 'whitelist.bypass' " +
"configuration of this service. This is NOT RECOMMENDED, for security reasons."
);
}
}