Add whitelist-prefix init-parameter to PageFlowPageFilter, since <url-pattern>/portlets/*.jsp</url-pattern> is invalid syntax and is not allowed by tomcat

This commit is contained in:
moparisthebest 2014-05-07 14:38:34 -04:00
parent 9295099ed5
commit cf6775dc87

View File

@ -67,6 +67,7 @@ public abstract class PageFlowPageFilter
private ServletContainerAdapter _servletContainerAdapter; private ServletContainerAdapter _servletContainerAdapter;
private FlowControllerFactory _flowControllerFactory; private FlowControllerFactory _flowControllerFactory;
private Map _knownModulePaths = new InternalConcurrentHashMap(); private Map _knownModulePaths = new InternalConcurrentHashMap();
private String whitelistPrefix = null;
protected PageFlowPageFilter() protected PageFlowPageFilter()
{ {
@ -92,6 +93,8 @@ public abstract class PageFlowPageFilter
_servletContainerAdapter = AdapterManager.getServletContainerAdapter( _servletContext ); _servletContainerAdapter = AdapterManager.getServletContainerAdapter( _servletContext );
_flowControllerFactory = FlowControllerFactory.get( _servletContext ); _flowControllerFactory = FlowControllerFactory.get( _servletContext );
whitelistPrefix = filterConfig.getInitParameter("whitelist-prefix");
} }
public void doFilter( ServletRequest request, ServletResponse response, FilterChain chain ) public void doFilter( ServletRequest request, ServletResponse response, FilterChain chain )
@ -116,6 +119,16 @@ public abstract class PageFlowPageFilter
} }
String servletPath = InternalUtils.getDecodedServletPath( httpRequest ); String servletPath = InternalUtils.getDecodedServletPath( httpRequest );
if (whitelistPrefix != null && !servletPath.startsWith(whitelistPrefix)) {
if (LOG.isDebugEnabled())
LOG.debug("Path " + servletPath +
" does not start with specified whitelist-prefix " + whitelistPrefix + ". Skipping filter.");
continueChainNoWrapper(request, response, chain);
return;
}
String extension = FileUtils.getFileExtension( servletPath ); String extension = FileUtils.getFileExtension( servletPath );
Set validFileExtensions = getValidFileExtensions(); Set validFileExtensions = getValidFileExtensions();