Commit 4f7730b3 authored by Simon Urli's avatar Simon Urli
Browse files

XCOMMONS-2347: ServletEnvironement#getResource should not return URL with relative path component

  * also catch IllegalArgumentException since Tomcat might throw them
    when trying to resolve a bad path
parent 945360aa
......@@ -84,7 +84,9 @@ public URL getResource(String resourceName)
if (url != null) {
url = url.toURI().normalize().toURL();
}
} catch (MalformedURLException | URISyntaxException e) {
// We're catching IllegalArgumentException which might be thrown by Tomcat when trying to resolve path such as
// `templates/../..`
} catch (MalformedURLException | URISyntaxException | IllegalArgumentException e) {
url = null;
this.logger.warn("Error getting resource [{}] because of invalid path format. Reason: [{}]",
resourceName, e.getMessage());
......
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment