[ jetty-Bugs-1302158 ] Jetty should return 400 for request ending with %

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[ jetty-Bugs-1302158 ] Jetty should return 400 for request ending with %

SourceForge.net
Bugs item #1302158, was opened at 2005-09-23 21:33
Message generated for change (Comment added) made by gregwilkins
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=107322&aid=1302158&group_id=7322

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: HTTP protocol
Group: None
Status: Open
>Resolution: Postponed
Priority: 5
Submitted By: Chandra (javaguru1729)
>Assigned to: Greg Wilkins (gregwilkins)
Summary: Jetty should return 400 for request ending with %

Initial Comment:
A request such as "<a href="http://localhost:8080/%">http://localhost:8080/%" is a bad
request. Jetty should return 400 Bad Request instead of
passing it to servlets and jsps. For instance, a
malformed request such
as "<a href="http://localhost:8080/ctx/hello1/%">http://localhost:8080/ctx/hello1/%" would invoke
JSP with 200 OK for the following configuration.

  <servlet>
    <servlet-name>hello1</servlet-name>
    <jsp-file>/hello1.jsp</jsp-file>
  </servlet>

  <servlet-mapping>
    <servlet-name>hello1</servlet-name>
    <url-pattern>/hello1/*</url-pattern>
  </servlet-mapping>


----------------------------------------------------------------------

>Comment By: Greg Wilkins (gregwilkins)
Date: 2005-10-06 19:55

Message:
Logged In: YES
user_id=44062

Most servers are strict in what they generate and forgiving
in what they accept.  While a trailing % is not legal, there
are many illegal URLs that servers accept.

Is there a specific reason that you believe this should be
rejected?  eg security or similar?

----------------------------------------------------------------------

You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=107322&aid=1302158&group_id=7322


-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
jetty-discuss mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/jetty-discuss