Fix empty URLs handling in ResourceUrlEncodingFilter
Prior to this commit, the ResourceUrlEncodingFilter would fail with a StringIndexOutOfBoundsException when: * the current request has a servlet context * the URL to encode is relative and is shorter than the context value This change defensively checks for those lengths and delegates to the parent implementation if necessary. Issue: SPR-13018
This commit is contained in:
@@ -73,10 +73,15 @@ public class ResourceUrlEncodingFilter extends OncePerRequestFilter {
|
|||||||
return super.encodeURL(url);
|
return super.encodeURL(url);
|
||||||
}
|
}
|
||||||
initIndexLookupPath(resourceUrlProvider);
|
initIndexLookupPath(resourceUrlProvider);
|
||||||
String prefix = url.substring(0, this.indexLookupPath);
|
if(url.length() >= this.indexLookupPath) {
|
||||||
String lookupPath = url.substring(this.indexLookupPath);
|
String prefix = url.substring(0, this.indexLookupPath);
|
||||||
lookupPath = resourceUrlProvider.getForLookupPath(lookupPath);
|
String lookupPath = url.substring(this.indexLookupPath);
|
||||||
return (lookupPath != null ? super.encodeURL(prefix + lookupPath) : super.encodeURL(url));
|
lookupPath = resourceUrlProvider.getForLookupPath(lookupPath);
|
||||||
|
if (lookupPath != null) {
|
||||||
|
return super.encodeURL(prefix + lookupPath);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return super.encodeURL(url);
|
||||||
}
|
}
|
||||||
|
|
||||||
private ResourceUrlProvider getResourceUrlProvider() {
|
private ResourceUrlProvider getResourceUrlProvider() {
|
||||||
|
|||||||
@@ -89,6 +89,23 @@ public class ResourceUrlEncodingFilterTests {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SPR-13018
|
||||||
|
@Test
|
||||||
|
public void encodeEmptyURLWithContext() throws Exception {
|
||||||
|
MockHttpServletRequest request = new MockHttpServletRequest("GET", "/context/foo");
|
||||||
|
request.setContextPath("/context");
|
||||||
|
request.setAttribute(ResourceUrlProviderExposingInterceptor.RESOURCE_URL_PROVIDER_ATTR, this.resourceUrlProvider);
|
||||||
|
MockHttpServletResponse response = new MockHttpServletResponse();
|
||||||
|
|
||||||
|
this.filter.doFilterInternal(request, response, new FilterChain() {
|
||||||
|
@Override
|
||||||
|
public void doFilter(ServletRequest request, ServletResponse response) throws IOException, ServletException {
|
||||||
|
String result = ((HttpServletResponse)response).encodeURL("?foo=1");
|
||||||
|
assertEquals("?foo=1", result);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
protected ResourceUrlProvider createResourceUrlProvider(List<ResourceResolver> resolvers) {
|
protected ResourceUrlProvider createResourceUrlProvider(List<ResourceResolver> resolvers) {
|
||||||
ResourceHttpRequestHandler handler = new ResourceHttpRequestHandler();
|
ResourceHttpRequestHandler handler = new ResourceHttpRequestHandler();
|
||||||
handler.setLocations(Arrays.asList(new ClassPathResource("test/", getClass())));
|
handler.setLocations(Arrays.asList(new ClassPathResource("test/", getClass())));
|
||||||
|
|||||||
Reference in New Issue
Block a user