Skip to content

Commit

Permalink
Merge pull request #7180 from eclipse/jetty-10.0.x-7160-EncodedPercen…
Browse files Browse the repository at this point in the history
…tUri

Issue #7160 - Add AMBIGUOUS_PATH_ENCODING to default UriCompliance mode.
  • Loading branch information
lachlan-roberts authored Nov 30, 2021
2 parents 2f5a822 + 7abb1e6 commit e409f35
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,9 @@ public String getDescription()
* additional violations to avoid most ambiguous URIs.
* This mode does allow {@link Violation#AMBIGUOUS_PATH_SEPARATOR}, but disallows all out {@link Violation}s.
*/
public static final UriCompliance DEFAULT = new UriCompliance("DEFAULT", of(Violation.AMBIGUOUS_PATH_SEPARATOR));
public static final UriCompliance DEFAULT = new UriCompliance("DEFAULT",
of(Violation.AMBIGUOUS_PATH_SEPARATOR,
Violation.AMBIGUOUS_PATH_ENCODING));

/**
* LEGACY compliance mode that models Jetty-9.4 behavior by allowing {@link Violation#AMBIGUOUS_PATH_SEGMENT},
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1812,13 +1812,18 @@ public void testAmbiguousEncoding() throws Exception
"Host: whatever\r\n" +
"\r\n";
_connector.getBean(HttpConnectionFactory.class).getHttpConfiguration().setUriCompliance(UriCompliance.DEFAULT);
assertThat(_connector.getResponse(request), startsWith("HTTP/1.1 400"));
assertThat(_connector.getResponse(request), startsWith("HTTP/1.1 200"));
_connector.getBean(HttpConnectionFactory.class).getHttpConfiguration().setUriCompliance(UriCompliance.LEGACY);
assertThat(_connector.getResponse(request), startsWith("HTTP/1.1 200"));
_connector.getBean(HttpConnectionFactory.class).getHttpConfiguration().setUriCompliance(UriCompliance.RFC3986);
assertThat(_connector.getResponse(request), startsWith("HTTP/1.1 200"));
_connector.getBean(HttpConnectionFactory.class).getHttpConfiguration().setUriCompliance(UriCompliance.UNSAFE);
assertThat(_connector.getResponse(request), startsWith("HTTP/1.1 200"));

UriCompliance custom = new UriCompliance("Custom", EnumSet.complementOf(
EnumSet.of(UriCompliance.Violation.AMBIGUOUS_PATH_ENCODING)));
_connector.getBean(HttpConnectionFactory.class).getHttpConfiguration().setUriCompliance(custom);
assertThat(_connector.getResponse(request), startsWith("HTTP/1.1 400"));
}

@Test
Expand Down

0 comments on commit e409f35

Please sign in to comment.