Joerg Hoh created SLING-13355:
---------------------------------
Summary: Make request error handlign aware of content-types
Key: SLING-13355
URL: https://issues.apache.org/jira/browse/SLING-13355
Project: Sling
Issue Type: New Feature
Components: Engine
Reporter: Joerg Hoh
Currently the error handling in the Sling Engine is not aware of the
content-type which has been already set.
For example I have this warn message:
{quote}
POST /content/dam/folder.initiateUpload.json HTTP/1.1]
org.apache.sling.engine.impl.SlingHttpServletResponseImpl Servlet
BundledScriptServlet (/libs/sling/servlet/errorhandler/404.jsp) tried to
override the 'Content-Type' header from 'application/json' to 'text/html'. This
is a violation of the RequestDispatcher.include() contract -
https://jakarta.ee/specifications/servlet/4.0/apidocs/javax/servlet/requestdispatcher#include-javax.servlet.ServletRequest-javax.servlet.ServletResponse-.
, Include stack: BundledScriptServlet
(/libs/sling/servlet/errorhandler/404.jsp)#1 ->
com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet#0. All
RequestProgressTracker messages:
[...]
310546 TIMER_END{771,ServletResolution}
URI=/content/dam/folder.initiateUpload.json handled by
Servlet=com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet
[...]
311308
TIMER_START{com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet#0}
311659 LOG Applying Error filters
[...]
311834 TIMER_START{handleError:status=404}
312328 TIMER_END{494,handleError:status=404} Using handler
BundledScriptServlet (/apps/sling/servlet/errorhandler/404.html)
312938
TIMER_START{resolveIncludedResource(/libs/sling/servlet/errorhandler/404.jsp)}
313050
TIMER_END{112,resolveIncludedResource(/libs/sling/servlet/errorhandler/404.jsp)}
path=/libs/sling/servlet/errorhandler/404.jsp resolves to
Resource=ServletResource, servlet=BundledScriptServlet
(/libs/sling/servlet/errorhandler/404.jsp),
path=/libs/sling/servlet/errorhandler/404.jsp
313062 LOG Including resource ServletResource, servlet=BundledScriptServlet
(/libs/sling/servlet/errorhandler/404.jsp),
path=/libs/sling/servlet/errorhandler/404.jsp (SlingRequestPathInfo:
path='/libs/sling/servlet/errorhandler/404.jsp',
selectorString='initiateUpload', extension='json', suffix='null')
313065 TIMER_START{resolveServlet(/libs/sling/servlet/errorhandler/404.jsp)}
313094 TIMER_END{28,resolveServlet(/libs/sling/servlet/errorhandler/404.jsp)}
Using servlet BundledScriptServlet (/libs/sling/servlet/errorhandler/404.jsp)
313345 TIMER_START{BundledScriptServlet
(/libs/sling/servlet/errorhandler/404.jsp)#1}
{quote}
Here the com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet
triggers the error handling of the Sling Engine (for whatever reason, but at
this point it already has set the content-type to "application/json". And as a
next step the error handler kicks in and writes the error messages with the
content-type text/html.
We should fix this for 2 reasons:
# It is a potential XSS (the browser's JSON parser encounters HTML markup)
# In my experience the default error handling frequently focuses on the the
"main request" only, that means it renders HTML; in some cases this error
handling is even configured to render full fledged HTML pages which can get
slow. This can be misused for DOS attacks, e.g. by requesting non-existing
images.
For this reason we should make the error handling aware of the requested
content-type and be able to register error handlers by status and content-type.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)