Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Sign in / Register
Toggle navigation
S
spring-boot
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
DEMO
spring-boot
Commits
e5a539d8
Commit
e5a539d8
authored
Apr 29, 2021
by
David Byron
Committed by
Stephane Nicoll
Jun 12, 2021
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Add configuration property for Tomcat's rejectIllegalHeader
See gh-26311
parent
c1c11760
Changes
4
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
with
40 additions
and
0 deletions
+40
-0
ServerProperties.java
...ingframework/boot/autoconfigure/web/ServerProperties.java
+13
-0
TomcatWebServerFactoryCustomizer.java
...figure/web/embedded/TomcatWebServerFactoryCustomizer.java
+12
-0
ServerPropertiesTests.java
...amework/boot/autoconfigure/web/ServerPropertiesTests.java
+7
-0
TomcatWebServerFactoryCustomizerTests.java
...e/web/embedded/TomcatWebServerFactoryCustomizerTests.java
+8
-0
No files found.
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/web/ServerProperties.java
View file @
e5a539d8
...
...
@@ -424,6 +424,11 @@ public class ServerProperties {
*/
private
final
Remoteip
remoteip
=
new
Remoteip
();
/**
* reject illegal header setting.
*/
private
Boolean
rejectIllegalHeader
;
public
DataSize
getMaxHttpFormPostSize
()
{
return
this
.
maxHttpFormPostSize
;
}
...
...
@@ -572,6 +577,14 @@ public class ServerProperties {
return
this
.
remoteip
;
}
public
Boolean
getRejectIllegalHeader
()
{
return
this
.
rejectIllegalHeader
;
}
public
void
setRejectIllegalHeader
(
Boolean
rejectIllegalHeader
)
{
this
.
rejectIllegalHeader
=
rejectIllegalHeader
;
}
/**
* Tomcat access log properties.
*/
...
...
spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/web/embedded/TomcatWebServerFactoryCustomizer.java
View file @
e5a539d8
...
...
@@ -117,6 +117,8 @@ public class TomcatWebServerFactoryCustomizer
.
to
((
relaxedChars
)
->
customizeRelaxedPathChars
(
factory
,
relaxedChars
));
propertyMapper
.
from
(
tomcatProperties:
:
getRelaxedQueryChars
).
as
(
this
::
joinCharacters
).
whenHasText
()
.
to
((
relaxedChars
)
->
customizeRelaxedQueryChars
(
factory
,
relaxedChars
));
propertyMapper
.
from
(
tomcatProperties:
:
getRejectIllegalHeader
).
whenNonNull
()
.
to
((
rejectIllegalHeader
)
->
customizeRejectIllegalHeader
(
factory
,
rejectIllegalHeader
));
customizeStaticResources
(
factory
);
customizeErrorReportValve
(
properties
.
getError
(),
factory
);
}
...
...
@@ -192,6 +194,16 @@ public class TomcatWebServerFactoryCustomizer
factory
.
addConnectorCustomizers
((
connector
)
->
connector
.
setProperty
(
"relaxedQueryChars"
,
relaxedChars
));
}
private
void
customizeRejectIllegalHeader
(
ConfigurableTomcatWebServerFactory
factory
,
boolean
rejectIllegalHeader
)
{
factory
.
addConnectorCustomizers
((
connector
)
->
{
ProtocolHandler
handler
=
connector
.
getProtocolHandler
();
if
(
handler
instanceof
AbstractHttp11Protocol
)
{
AbstractHttp11Protocol
<?>
protocol
=
(
AbstractHttp11Protocol
<?>)
handler
;
protocol
.
setRejectIllegalHeader
(
rejectIllegalHeader
);
}
});
}
private
String
joinCharacters
(
List
<
Character
>
content
)
{
return
content
.
stream
().
map
(
String:
:
valueOf
).
collect
(
Collectors
.
joining
());
}
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/web/ServerPropertiesTests.java
View file @
e5a539d8
...
...
@@ -130,6 +130,7 @@ class ServerPropertiesTests {
map
.
put
(
"server.tomcat.remoteip.protocol-header"
,
"X-Forwarded-Protocol"
);
map
.
put
(
"server.tomcat.remoteip.remote-ip-header"
,
"Remote-Ip"
);
map
.
put
(
"server.tomcat.remoteip.internal-proxies"
,
"10\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}"
);
map
.
put
(
"server.tomcat.reject-illegal-header"
,
"true"
);
map
.
put
(
"server.tomcat.background-processor-delay"
,
"10"
);
map
.
put
(
"server.tomcat.relaxed-path-chars"
,
"|,<"
);
map
.
put
(
"server.tomcat.relaxed-query-chars"
,
"^ , | "
);
...
...
@@ -152,6 +153,7 @@ class ServerPropertiesTests {
assertThat
(
tomcat
.
getRemoteip
().
getRemoteIpHeader
()).
isEqualTo
(
"Remote-Ip"
);
assertThat
(
tomcat
.
getRemoteip
().
getProtocolHeader
()).
isEqualTo
(
"X-Forwarded-Protocol"
);
assertThat
(
tomcat
.
getRemoteip
().
getInternalProxies
()).
isEqualTo
(
"10\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}"
);
assertThat
(
tomcat
.
getRejectIllegalHeader
()).
isTrue
();
assertThat
(
tomcat
.
getBackgroundProcessorDelay
()).
hasSeconds
(
10
);
assertThat
(
tomcat
.
getRelaxedPathChars
()).
containsExactly
(
'|'
,
'<'
);
assertThat
(
tomcat
.
getRelaxedQueryChars
()).
containsExactly
(
'^'
,
'|'
);
...
...
@@ -405,6 +407,11 @@ class ServerPropertiesTests {
.
isEqualTo
(
new
RemoteIpValve
().
getInternalProxies
());
}
@Test
void
tomcatRejectIllegalHeaderDefaultsToNull
()
{
assertThat
(
this
.
properties
.
getTomcat
().
getRejectIllegalHeader
()).
isNull
();
}
@Test
void
tomcatUseRelativeRedirectsDefaultsToFalse
()
{
assertThat
(
this
.
properties
.
getTomcat
().
isUseRelativeRedirects
()).
isFalse
();
...
...
spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/web/embedded/TomcatWebServerFactoryCustomizerTests.java
View file @
e5a539d8
...
...
@@ -320,6 +320,14 @@ class TomcatWebServerFactoryCustomizerTests {
assertThat
(
factory
.
getEngineValves
()).
isEmpty
();
}
@Test
void
testCustomizeRejectIllegalHeader
()
{
bind
(
"server.tomcat.reject-illegal-header=false"
);
customizeAndRunServer
((
server
)
->
assertThat
(
((
AbstractHttp11Protocol
<?>)
server
.
getTomcat
().
getConnector
().
getProtocolHandler
())
.
getRejectIllegalHeader
()).
isFalse
());
}
@Test
void
errorReportValveIsConfiguredToNotReportStackTraces
()
{
TomcatWebServer
server
=
customizeAndGetServer
();
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment