Can a WSRP Portlet introduce malicious JavaScript?
First, there should be some level of trust established between the Producer and Consumer during the registration process. In most cases, an HTTP transport binding is used, and XML is transferred across the wire between Producer and Consumer. This XML most often contains markup fragments of HTML, which in turn could contain client-side JavaScript. Due to inherent client-side JavaScript limitations , it is not thought that this will be a large concern for Consumers.