Consider having HeaderWriters check before writing
All HeadersWriter only write Header if its not already written. Fixes: gh-6454 gh-5193
This commit is contained in:
committed by
Josh Cummings
parent
4742c18e4b
commit
93d6a38ffd
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2016 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -73,6 +73,7 @@ import javax.servlet.http.HttpServletResponse;
|
||||
* </p>
|
||||
*
|
||||
* @author Joe Grandja
|
||||
* @author Ankur Pathak
|
||||
* @since 4.1
|
||||
*/
|
||||
public final class ContentSecurityPolicyHeaderWriter implements HeaderWriter {
|
||||
@@ -100,7 +101,10 @@ public final class ContentSecurityPolicyHeaderWriter implements HeaderWriter {
|
||||
*/
|
||||
@Override
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
response.setHeader((!reportOnly ? CONTENT_SECURITY_POLICY_HEADER : CONTENT_SECURITY_POLICY_REPORT_ONLY_HEADER), policyDirectives);
|
||||
String headerName = !reportOnly ? CONTENT_SECURITY_POLICY_HEADER : CONTENT_SECURITY_POLICY_REPORT_ONLY_HEADER;
|
||||
if (!response.containsHeader(headerName)) {
|
||||
response.setHeader(headerName, policyDirectives);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2018 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -33,6 +33,7 @@ import org.springframework.util.Assert;
|
||||
* responsible for declaring the restrictions for a particular feature type.
|
||||
*
|
||||
* @author Vedran Pavic
|
||||
* @author Ankur Pathak
|
||||
* @since 5.1
|
||||
*/
|
||||
public final class FeaturePolicyHeaderWriter implements HeaderWriter {
|
||||
@@ -54,7 +55,9 @@ public final class FeaturePolicyHeaderWriter implements HeaderWriter {
|
||||
|
||||
@Override
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
response.setHeader(FEATURE_POLICY_HEADER, this.policyDirectives);
|
||||
if (!response.containsHeader(FEATURE_POLICY_HEADER)) {
|
||||
response.setHeader(FEATURE_POLICY_HEADER, this.policyDirectives);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2016 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -100,6 +100,7 @@ import java.util.Map;
|
||||
* </p>
|
||||
*
|
||||
* @author Tim Ysewyn
|
||||
* @author Ankur Pathak
|
||||
* @since 4.1
|
||||
*/
|
||||
public final class HpkpHeaderWriter implements HeaderWriter {
|
||||
@@ -174,7 +175,10 @@ public final class HpkpHeaderWriter implements HeaderWriter {
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
if (requestMatcher.matches(request)) {
|
||||
if (!pins.isEmpty()) {
|
||||
response.setHeader(reportOnly ? HPKP_RO_HEADER_NAME : HPKP_HEADER_NAME, hpkpHeaderValue);
|
||||
String headerName = reportOnly ? HPKP_RO_HEADER_NAME : HPKP_HEADER_NAME;
|
||||
if (!response.containsHeader(headerName)) {
|
||||
response.setHeader(headerName, hpkpHeaderValue);
|
||||
}
|
||||
} if (logger.isDebugEnabled()) {
|
||||
logger.debug("Not injecting HPKP header since there aren't any pins");
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2013 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -53,6 +53,7 @@ import org.springframework.util.Assert;
|
||||
* </p>
|
||||
*
|
||||
* @author Rob Winch
|
||||
* @author Ankur Pathak
|
||||
* @since 3.2
|
||||
*/
|
||||
public final class HstsHeaderWriter implements HeaderWriter {
|
||||
@@ -159,7 +160,9 @@ public final class HstsHeaderWriter implements HeaderWriter {
|
||||
*/
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
if (this.requestMatcher.matches(request)) {
|
||||
response.setHeader(HSTS_HEADER_NAME, this.hstsHeaderValue);
|
||||
if (!response.containsHeader(HSTS_HEADER_NAME)) {
|
||||
response.setHeader(HSTS_HEADER_NAME, this.hstsHeaderValue);
|
||||
}
|
||||
}
|
||||
else if (this.logger.isDebugEnabled()) {
|
||||
this.logger
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2016 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -49,6 +49,7 @@ import org.springframework.util.Assert;
|
||||
*
|
||||
* @author Eddú Meléndez
|
||||
* @author Kazuki Shimizu
|
||||
* @author Ankur Pathak
|
||||
* @since 4.2
|
||||
*/
|
||||
public class ReferrerPolicyHeaderWriter implements HeaderWriter {
|
||||
@@ -89,7 +90,9 @@ public class ReferrerPolicyHeaderWriter implements HeaderWriter {
|
||||
*/
|
||||
@Override
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
response.setHeader(REFERRER_POLICY_HEADER, this.policy.getPolicy());
|
||||
if (!response.containsHeader(REFERRER_POLICY_HEADER)) {
|
||||
response.setHeader(REFERRER_POLICY_HEADER, this.policy.getPolicy());
|
||||
}
|
||||
}
|
||||
|
||||
public enum ReferrerPolicy {
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2016 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -30,6 +30,7 @@ import org.springframework.util.Assert;
|
||||
*
|
||||
* @author Marten Deinum
|
||||
* @author Rob Winch
|
||||
* @author Ankur Pathak
|
||||
* @since 3.2
|
||||
*/
|
||||
public class StaticHeadersWriter implements HeaderWriter {
|
||||
@@ -56,8 +57,10 @@ public class StaticHeadersWriter implements HeaderWriter {
|
||||
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
for (Header header : headers) {
|
||||
for (String value : header.getValues()) {
|
||||
response.addHeader(header.getName(), value);
|
||||
if (!response.containsHeader(header.getName())) {
|
||||
for (String value : header.getValues()) {
|
||||
response.addHeader(header.getName(), value);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -66,4 +69,4 @@ public class StaticHeadersWriter implements HeaderWriter {
|
||||
public String toString() {
|
||||
return getClass().getName() + " [headers=" + headers + "]";
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2013 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -26,6 +26,7 @@ import org.springframework.security.web.header.HeaderWriter;
|
||||
* >X-XSS-Protection header</a>.
|
||||
*
|
||||
* @author Rob Winch
|
||||
* @author Ankur Pathak
|
||||
* @since 3.2
|
||||
*/
|
||||
public final class XXssProtectionHeaderWriter implements HeaderWriter {
|
||||
@@ -47,7 +48,9 @@ public final class XXssProtectionHeaderWriter implements HeaderWriter {
|
||||
}
|
||||
|
||||
public void writeHeaders(HttpServletRequest request, HttpServletResponse response) {
|
||||
response.setHeader(XSS_PROTECTION_HEADER, headerValue);
|
||||
if (!response.containsHeader(XSS_PROTECTION_HEADER)) {
|
||||
response.setHeader(XSS_PROTECTION_HEADER, headerValue);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2002-2018 the original author or authors.
|
||||
* Copyright 2002-2019 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -27,6 +27,7 @@ import javax.servlet.http.HttpServletResponse;
|
||||
*
|
||||
* @author Marten Deinum
|
||||
* @author Rob Winch
|
||||
* @author Ankur Pathak
|
||||
* @since 3.2
|
||||
*
|
||||
* @see AllowFromStrategy
|
||||
@@ -84,10 +85,14 @@ public final class XFrameOptionsHeaderWriter implements HeaderWriter {
|
||||
if (XFrameOptionsMode.ALLOW_FROM.equals(frameOptionsMode)) {
|
||||
String allowFromValue = this.allowFromStrategy.getAllowFromValue(request);
|
||||
if (XFrameOptionsMode.DENY.getMode().equals(allowFromValue)) {
|
||||
response.setHeader(XFRAME_OPTIONS_HEADER, XFrameOptionsMode.DENY.getMode());
|
||||
if (!response.containsHeader(XFRAME_OPTIONS_HEADER)) {
|
||||
response.setHeader(XFRAME_OPTIONS_HEADER, XFrameOptionsMode.DENY.getMode());
|
||||
}
|
||||
} else if (allowFromValue != null) {
|
||||
response.setHeader(XFRAME_OPTIONS_HEADER,
|
||||
XFrameOptionsMode.ALLOW_FROM.getMode() + " " + allowFromValue);
|
||||
if (!response.containsHeader(XFRAME_OPTIONS_HEADER)) {
|
||||
response.setHeader(XFRAME_OPTIONS_HEADER,
|
||||
XFrameOptionsMode.ALLOW_FROM.getMode() + " " + allowFromValue);
|
||||
}
|
||||
}
|
||||
}
|
||||
else {
|
||||
|
||||
Reference in New Issue
Block a user