【问题标题】:Spring MVC application filtering HTML in URL - Is this a security issue?Spring MVC 应用程序在 URL 中过滤 HTML - 这是一个安全问题吗?
【发布时间】:2022-01-19 14:56:08
【问题描述】:

我现有的 Spring Web MVC 应用程序在 Controller 中有以下处理程序映射。

    @RequestMapping(method = RequestMethod.GET, value = "/welcome")

我触发了以下请求http://www.example.com/welcome,这工作正常。

问题是

http://www.example.com/welcome.check.blah 

也有效!!!

此外,带有脚本标记的应用程序的 HTTP GET 请求 URL 正在重新显示,尽管它未通过授权。

示例http://www.example.com/welcome<script>alert("hi")</script> 在浏览器窗口中重新显示,并且由于我的授权逻辑“未授权”消息显示。

我想知道这是否是一个安全问题,我是否需要在代码中进行任何编码/过滤?

【问题讨论】:

    标签: java spring security http spring-mvc


    【解决方案1】:

    这种行为是由于 useSuffixPatternMatch 选项在 RequestMappingHandlerMapping 中默认为真(我假设您使用 Spring MVC 3.1)。

    使用SuffixPatternMatch: 将模式匹配到请求时是否使用后缀模式匹配(“.*”)。如果启用,映射到“/users”的方法也匹配到“/users.*”。默认值为“真”。

    要将useSuffixPatternMatch设置为false,最简单的方法是使用@Configuration:

    @Configuration
    @EnableWebMvc
    public class Api extends WebMvcConfigurationSupport {
    
        @Override
        public RequestMappingHandlerMapping requestMappingHandlerMapping() {
            RequestMappingHandlerMapping mapping = super.requestMappingHandlerMapping();
            mapping.setUseSuffixPatternMatch(false);
            return mapping;
        }
    
    }
    

    【讨论】:

    • 感谢您指出usesuffixPatternMatch。会尝试的。您对另一点有任何意见吗?这是一个安全问题吗?我们可以阻止浏览器重新显示输入的 URL 吗?
    • 我测试了它,是的,URL 被重新显示,但
    【解决方案2】:

    在当前的 Spring Java 配置中,有一种稍微简单的方法来配置相同的东西:

    @Configuration
    public class DispatcherConfig extends WebMvcConfigurationSupport {
    
        @Override
        protected void configurePathMatch(PathMatchConfigurer configurer) {
            configurer.setUseSuffixPatternMatch(false);
        }
    
    }
    

    【讨论】:

      【解决方案3】:

      当您使用 Spring 请求该类型的映射(即“/anything”)时,Spring 实际上将您的控制器映射到多个 URL:

      /欢迎
      /欢迎。*
      /欢迎/

      为防止这种情况发生 - 在 RequestMapping 时更具体(即 /welcome.htm ),或手动将 URL 映射到 Xml 配置中的控制器:

      <bean class="org.springframework.web.servlet.handler.SimpleUrlHandlerMapping">
              <property name="mappings">
                  <props>
                      <prop key="/welcome">YourControllerBean</prop>
                  </props>
              </property>
      </bean>
      


      干杯,皮特

      【讨论】:

      • 感谢您的回复。但是我已经在使用基于注释的请求处理程序映射,我不能使用“.htm”后缀:(
      【解决方案4】:

      您也可以在 web.xml 中通过提及 url 模式来限制这一点。您可以在 web.xml 中提及“/.htm”,而不是给出“/”。

      有点像

      <servlet-mapping>
              <servlet-name>dispatcher</servlet-name>
              <url-pattern>/application/*.htm</url-pattern>
          </servlet-mapping>
      

      【讨论】:

      • 不幸的是,我不能这样做。传入请求的格式为“/welcome?key=value”,而不是“/welcome.html”。这样做是为了掩盖底层技术。
      • 哦,好吧..可以接受...但对我来说,它并没有透露任何底层技术,而是指定了 url 模式......
      【解决方案5】:

      您可以使用useDefaultSuffixPattern 属性。

      <bean class="org.springframework.web.servlet.mvc.annotation.DefaultAnnotationHandlerMapping">
          <property name="useDefaultSuffixPattern" value="false" />
      </bean>
      

      另请参阅URL Pattern Restricting in SPRING MVC

      【讨论】:

        【解决方案6】:

        从 Spring 框架 5.3 开始,useDefaultSuffixPattern 已被弃用并默认关闭。春季升级笔记,section "Use of Path Extensions Deprecated in Spring MVC"

        【讨论】:

          猜你喜欢
          • 1970-01-01
          • 1970-01-01
          • 1970-01-01
          • 1970-01-01
          • 1970-01-01
          • 2016-08-23
          • 2018-10-22
          • 2019-04-07
          • 1970-01-01
          相关资源
          最近更新 更多