mirror of
https://github.com/spring-projects/spring-framework.git
synced 2026-09-17 16:39:29 +00:00
Update valid path checks for double encoding
See gh-33687
This commit is contained in:
+16
-12
@@ -152,24 +152,28 @@ public abstract class ResourceHandlerUtils {
|
||||
|
||||
private static boolean isInvalidEncodedPath(String path) {
|
||||
if (path.contains("%")) {
|
||||
try {
|
||||
// Use URLDecoder (vs UriUtils) to preserve potentially decoded UTF-8 chars
|
||||
String decodedPath = URLDecoder.decode(path, StandardCharsets.UTF_8);
|
||||
if (isInvalidPath(decodedPath)) {
|
||||
return true;
|
||||
}
|
||||
decodedPath = normalizeInputPath(decodedPath);
|
||||
if (isInvalidPath(decodedPath)) {
|
||||
return true;
|
||||
}
|
||||
String decodedPath = decode(path);
|
||||
if (decodedPath.contains("%")) {
|
||||
decodedPath = decode(decodedPath);
|
||||
}
|
||||
catch (IllegalArgumentException ex) {
|
||||
// May not be possible to decode...
|
||||
if (isInvalidPath(decodedPath)) {
|
||||
return true;
|
||||
}
|
||||
decodedPath = normalizeInputPath(decodedPath);
|
||||
return isInvalidPath(decodedPath);
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
private static String decode(String path) {
|
||||
try {
|
||||
return URLDecoder.decode(path, StandardCharsets.UTF_8);
|
||||
}
|
||||
catch (Exception ex) {
|
||||
return "";
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Create a resource relative to the given {@link Resource}, also decoding
|
||||
* the resource path for a {@link UrlResource}.
|
||||
|
||||
+17
-12
@@ -157,24 +157,29 @@ public abstract class ResourceHandlerUtils {
|
||||
*/
|
||||
private static boolean isInvalidEncodedPath(String path) {
|
||||
if (path.contains("%")) {
|
||||
try {
|
||||
// Use URLDecoder (vs UriUtils) to preserve potentially decoded UTF-8 chars
|
||||
String decodedPath = URLDecoder.decode(path, StandardCharsets.UTF_8);
|
||||
if (isInvalidPath(decodedPath)) {
|
||||
return true;
|
||||
}
|
||||
decodedPath = normalizeInputPath(decodedPath);
|
||||
if (isInvalidPath(decodedPath)) {
|
||||
return true;
|
||||
}
|
||||
String decodedPath = decode(path);
|
||||
if (decodedPath.contains("%")) {
|
||||
decodedPath = decode(decodedPath);
|
||||
}
|
||||
catch (IllegalArgumentException ex) {
|
||||
// May not be possible to decode...
|
||||
if (isInvalidPath(decodedPath)) {
|
||||
return true;
|
||||
}
|
||||
decodedPath = normalizeInputPath(decodedPath);
|
||||
return isInvalidPath(decodedPath);
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
private static String decode(String path) {
|
||||
try {
|
||||
return URLDecoder.decode(path, StandardCharsets.UTF_8);
|
||||
}
|
||||
catch (Exception ex) {
|
||||
return "";
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* Check whether the resource is under the given location.
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user