This is an automated email from the ASF dual-hosted git repository.

joerghoh pushed a commit to branch master
in repository 
https://gitbox.apache.org/repos/asf/sling-org-apache-sling-engine.git


The following commit(s) were added to refs/heads/master by this push:
     new d6feb03  SLING-13365 fail by default when providing more than 10'000 
parameters (#96)
d6feb03 is described below

commit d6feb03dace3dd7763aea81e8f54f14a42ac33b4
Author: Jörg Hoh <[email protected]>
AuthorDate: Tue Sep 29 12:04:48 2026 +0200

    SLING-13365 fail by default when providing more than 10'000 parameters (#96)
---
 .../sling/engine/impl/parameters/ParameterMap.java |  2 +-
 .../RequestParameterSupportConfigurer.java         |  7 +++--
 .../engine/impl/SlingRequestProcessorImplTest.java | 33 ++++++++++++++++++----
 .../engine/impl/parameters/ParameterMapTest.java   |  4 +--
 4 files changed, 34 insertions(+), 12 deletions(-)

diff --git 
a/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java 
b/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
index 884fd5b..ca0b1ba 100644
--- a/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
+++ b/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
@@ -78,7 +78,7 @@ public class ParameterMap extends LinkedHashMap<String, 
RequestParameter[]> impl
         // check number of parameters
         if (maxParameters > -1 && this.requestParameters.size() >= 
maxParameters) {
             if (failOnParameterLimit) {
-                throw new IllegalStateException("Too many name/value pairs, 
limit is " + maxParameters);
+                throw new SlingParameterParseException("Too many name/value 
pairs, limit is " + maxParameters, null);
             }
             LoggerFactory.getLogger(Util.class)
                     .warn("Too many name/value pairs, stopped processing after 
" + maxParameters + " entries");
diff --git 
a/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
 
b/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
index 7421b46..f1e6f20 100644
--- 
a/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
+++ 
b/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
@@ -132,9 +132,10 @@ public class RequestParameterSupportConfigurer implements 
Filter {
         @AttributeDefinition(
                 name = "Fail on Parameter Limit",
                 description = "Whether to throw an exception when the maximum 
number of parameters is exceeded. "
-                        + "If false (default), a warning is logged and 
processing continues with truncated parameters. "
-                        + "If true, an IllegalStateException is thrown.")
-        boolean sling_default_parameter_fail_on_limit() default false;
+                        + "If true (default), an exception is thrown and the 
request is rejected with a 400 Bad "
+                        + "Request response. If false, a warning is logged and 
processing continues with the "
+                        + "parameter map silently truncated after the 
configured limit.")
+        boolean sling_default_parameter_fail_on_limit() default true;
     }
 
     static final String PID = "org.apache.sling.engine.parameters";
diff --git 
a/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java 
b/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
index 2a4a160..8f38a40 100644
--- 
a/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
+++ 
b/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
@@ -54,7 +54,8 @@ import static org.mockito.Mockito.when;
 /**
  * Tests for {@link SlingRequestProcessorImpl}, in particular the
  * {@code SlingParameterParseException} to HTTP 400 mapping performed in
- * {@code doProcessRequest}.
+ * {@code doProcessRequest} (regression tests for SLING-13364 and
+ * SLING-13138).
  */
 public class SlingRequestProcessorImplTest {
 
@@ -105,11 +106,31 @@ public class SlingRequestProcessorImplTest {
      * instead of propagating as a server error or being swallowed.
      */
     @Test
-    public void testDoProcessRequestMapsParameterParseExceptionToBadRequest() 
throws Exception {
+    public void 
testDoProcessRequestMapsSlingParameterParseExceptionToBadRequest() throws 
Exception {
+        assertDoProcessRequestMapsExceptionToBadRequest(
+                new SlingParameterParseException("Error parsing query string", 
new IllegalArgumentException("bad")),
+                "Error parsing query string");
+    }
+
+    /**
+     * {@link SlingParameterParseException} raised while servicing a request
+     * (here simulated by the resolved servlet, standing in for the parameter
+     * limit check that {@code RequestData.service} triggers indirectly via
+     * {@code ParameterMap.addParameter}) must be caught by
+     * {@code doProcessRequest} and mapped to a 400 response, instead of
+     * propagating as a server error.
+     */
+    @Test
+    public void testDoProcessRequestMapsParameterLimitExceptionToBadRequest() 
throws Exception {
+        assertDoProcessRequestMapsExceptionToBadRequest(
+                new SlingParameterParseException("Too many name/value pairs, 
limit is 10000", null),
+                "Too many name/value pairs");
+    }
+
+    private void assertDoProcessRequestMapsExceptionToBadRequest(
+            final RuntimeException exceptionToThrow, final String 
expectedMessageFragment) throws Exception {
         final Servlet servlet = mock(Servlet.class);
-        doThrow(new SlingParameterParseException("Error parsing query string", 
new IllegalArgumentException("bad")))
-                .when(servlet)
-                .service(any(ServletRequest.class), 
any(ServletResponse.class));
+        
doThrow(exceptionToThrow).when(servlet).service(any(ServletRequest.class), 
any(ServletResponse.class));
 
         final Resource resource = getMockedResource("/content/test");
 
@@ -141,7 +162,7 @@ public class SlingRequestProcessorImplTest {
 
         verify(httpServletResponse).setStatus(SC_BAD_REQUEST);
         writer.flush();
-        assertTrue(writer.toString().contains("Error parsing query string"));
+        assertTrue(writer.toString().contains(expectedMessageFragment));
     }
 
     private static @NotNull Resource getMockedResource(final @NotNull String 
path) {
diff --git 
a/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java 
b/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
index a89e279..258fbfc 100644
--- 
a/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
+++ 
b/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
@@ -76,7 +76,7 @@ public class ParameterMapTest {
         assertEquals(2, pm.size());
 
         // Should throw exception when exceeding limit
-        exception.expect(IllegalStateException.class);
+        exception.expect(SlingParameterParseException.class);
         exception.expectMessage("Too many name/value pairs");
         exception.expectMessage("2");
         pm.addParameter(createTestParameter("param3", "value3"), false);
@@ -123,7 +123,7 @@ public class ParameterMapTest {
         assertEquals(5, pm.size());
 
         // Next should fail
-        exception.expect(IllegalStateException.class);
+        exception.expect(SlingParameterParseException.class);
         exception.expectMessage("Too many name/value pairs");
         exception.expectMessage("5");
         pm.addParameter(createTestParameter("param6", "value6"), false);

Reply via email to