Class RequestPathFilter

  • All Implemented Interfaces:
    javax.servlet.Filter

    public class RequestPathFilter
    extends Object
    implements javax.servlet.Filter
    Reject any request with an invalid path (i.e., HttpServletRequest.getPathInfo()).

    The decoded request path must be a single-line string without any parent path segments ("../"). For more details, see validPath().

    Note: Currently also rejecting strings that contain any less than ("<"), greater than (">"), or backslash ("\") characters. [May loosen this restriction later.]

    Since:
    3.16.47
    See Also:
    StringValidateEncodeUtils.validPath(String)
    • Constructor Detail

      • RequestPathFilter

        public RequestPathFilter()
    • Method Detail

      • init

        public void init​(javax.servlet.FilterConfig filterConfig)
                  throws javax.servlet.ServletException
        Specified by:
        init in interface javax.servlet.Filter
        Throws:
        javax.servlet.ServletException
      • destroy

        public void destroy()
        Specified by:
        destroy in interface javax.servlet.Filter
      • doFilter

        public void doFilter​(javax.servlet.ServletRequest servletRequest,
                             javax.servlet.ServletResponse servletResponse,
                             javax.servlet.FilterChain filterChain)
                      throws IOException,
                             javax.servlet.ServletException
        Specified by:
        doFilter in interface javax.servlet.Filter
        Throws:
        IOException
        javax.servlet.ServletException