Decode static resource path with UriUtils

See gh-33859
This commit is contained in:
rstoyanchev
2024-11-12 11:39:10 +00:00
parent 9dabfdf0bf
commit cbe2f36106
2 changed files with 25 additions and 24 deletions

View File

@@ -196,23 +196,23 @@ public abstract class ResourceHandlerUtils {
}
private static boolean isInvalidEncodedPath(String path) {
if (path.contains("%")) {
String decodedPath = decode(path);
if (decodedPath.contains("%")) {
decodedPath = decode(decodedPath);
}
if (isInvalidPath(decodedPath)) {
return true;
}
decodedPath = normalizeInputPath(decodedPath);
return isInvalidPath(decodedPath);
String decodedPath = decode(path);
if (decodedPath.contains("%")) {
decodedPath = decode(decodedPath);
}
return false;
if (!StringUtils.hasText(decodedPath)) {
return true;
}
if (isInvalidPath(decodedPath)) {
return true;
}
decodedPath = normalizeInputPath(decodedPath);
return isInvalidPath(decodedPath);
}
private static String decode(String path) {
try {
return URLDecoder.decode(path, StandardCharsets.UTF_8);
return UriUtils.decode(path, StandardCharsets.UTF_8);
}
catch (Exception ex) {
return "";