Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Sign in / Register
Toggle navigation
S
spring-boot
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
DEMO
spring-boot
Commits
ed734d7e
Commit
ed734d7e
authored
Jun 06, 2018
by
Madhura Bhave
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Trace filter ignores invalid requests
Fixes gh-12987
parent
59746de6
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
25 additions
and
0 deletions
+25
-0
HttpTraceFilter.java
...ework/boot/actuate/web/trace/servlet/HttpTraceFilter.java
+16
-0
HttpTraceFilterTests.java
...boot/actuate/trace/http/servlet/HttpTraceFilterTests.java
+9
-0
No files found.
spring-boot-project/spring-boot-actuator/src/main/java/org/springframework/boot/actuate/web/trace/servlet/HttpTraceFilter.java
View file @
ed734d7e
...
...
@@ -17,6 +17,8 @@
package
org
.
springframework
.
boot
.
actuate
.
web
.
trace
.
servlet
;
import
java.io.IOException
;
import
java.net.URI
;
import
java.net.URISyntaxException
;
import
javax.servlet.Filter
;
import
javax.servlet.FilterChain
;
...
...
@@ -76,6 +78,10 @@ public class HttpTraceFilter extends OncePerRequestFilter implements Ordered {
protected
void
doFilterInternal
(
HttpServletRequest
request
,
HttpServletResponse
response
,
FilterChain
filterChain
)
throws
ServletException
,
IOException
{
if
(!
isRequestValid
(
request
))
{
filterChain
.
doFilter
(
request
,
response
);
return
;
}
TraceableHttpServletRequest
traceableRequest
=
new
TraceableHttpServletRequest
(
request
);
HttpTrace
trace
=
this
.
tracer
.
receivedRequest
(
traceableRequest
);
...
...
@@ -95,6 +101,16 @@ public class HttpTraceFilter extends OncePerRequestFilter implements Ordered {
}
}
private
boolean
isRequestValid
(
HttpServletRequest
request
)
{
try
{
new
URI
(
request
.
getRequestURL
().
toString
());
return
true
;
}
catch
(
URISyntaxException
ex
)
{
return
false
;
}
}
private
String
getSessionId
(
HttpServletRequest
request
)
{
HttpSession
session
=
request
.
getSession
(
false
);
return
(
session
!=
null
?
session
.
getId
()
:
null
);
...
...
spring-boot-project/spring-boot-actuator/src/test/java/org/springframework/boot/actuate/trace/http/servlet/HttpTraceFilterTests.java
View file @
ed734d7e
...
...
@@ -127,4 +127,13 @@ public class HttpTraceFilterTests {
}
}
@Test
public
void
filterRejectsInvalidRequests
()
throws
ServletException
,
IOException
{
MockHttpServletRequest
request
=
new
MockHttpServletRequest
();
request
.
setServerName
(
"<script>alert(document.domain)</script>"
);
this
.
filter
.
doFilter
(
request
,
new
MockHttpServletResponse
(),
new
MockFilterChain
());
assertThat
(
this
.
repository
.
findAll
()).
hasSize
(
0
);
}
}
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment