Ticket #103 (closed enhancement: fixed)

Opened 2 years ago

Last modified 2 years ago

Reject invalid requests before creating sessions

Reported by: MartinLeidig Owned by: MartinLeidig
Priority: major Milestone: 0.15.0
Component: Core (general) Version:
Keywords: Cc:

Description

Requests being obviously invalid should be rejected before running in session redirection handling and unncessarily creating sessions. A common example are requests caused by broken relative image links with a missing trailing slash which are interpreted relative to the servlet path and cause unnecessary session creation.

Change History

Changed 2 years ago by MartinLeidig

  • status changed from new to closed
  • resolution set to fixed

Added validateRequest() method to HttpRequestHandler? base class, which can be overridden and return an HTTP error code. The ContextHttpRequestHandler? implementation by default simply checks the page name and returns a 404 if it contains slashes.

Changed 2 years ago by MartinLeidig

  • milestone changed from 0.14.8 to 0.15.0
Note: See TracTickets for help on using tickets.