Joerg Hoh created SLING-13355:
---------------------------------

             Summary: Make request error handlign aware of content-types
                 Key: SLING-13355
                 URL: https://issues.apache.org/jira/browse/SLING-13355
             Project: Sling
          Issue Type: New Feature
          Components: Engine
            Reporter: Joerg Hoh


Currently the error handling in the Sling Engine is not aware of the 
content-type which has been already set.

For example I have this warn message:
{quote}
POST /content/dam/folder.initiateUpload.json HTTP/1.1] 
org.apache.sling.engine.impl.SlingHttpServletResponseImpl Servlet 
BundledScriptServlet (/libs/sling/servlet/errorhandler/404.jsp) tried to 
override the 'Content-Type' header from 'application/json' to 'text/html'. This 
is a violation of the RequestDispatcher.include() contract - 
https://jakarta.ee/specifications/servlet/4.0/apidocs/javax/servlet/requestdispatcher#include-javax.servlet.ServletRequest-javax.servlet.ServletResponse-.
 , Include stack: BundledScriptServlet 
(/libs/sling/servlet/errorhandler/404.jsp)#1 -> 
com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet#0. All 
RequestProgressTracker messages: 
[...]
310546 TIMER_END{771,ServletResolution} 
URI=/content/dam/folder.initiateUpload.json handled by 
Servlet=com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet
[...]
311308 
TIMER_START{com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet#0}
 311659 LOG Applying Error filters
[...]
 311834 TIMER_START{handleError:status=404}
 312328 TIMER_END{494,handleError:status=404} Using handler 
BundledScriptServlet (/apps/sling/servlet/errorhandler/404.html)
 312938 
TIMER_START{resolveIncludedResource(/libs/sling/servlet/errorhandler/404.jsp)}
 313050 
TIMER_END{112,resolveIncludedResource(/libs/sling/servlet/errorhandler/404.jsp)}
 path=/libs/sling/servlet/errorhandler/404.jsp resolves to 
Resource=ServletResource, servlet=BundledScriptServlet 
(/libs/sling/servlet/errorhandler/404.jsp), 
path=/libs/sling/servlet/errorhandler/404.jsp
 313062 LOG Including resource ServletResource, servlet=BundledScriptServlet 
(/libs/sling/servlet/errorhandler/404.jsp), 
path=/libs/sling/servlet/errorhandler/404.jsp (SlingRequestPathInfo: 
path='/libs/sling/servlet/errorhandler/404.jsp', 
selectorString='initiateUpload', extension='json', suffix='null')
 313065 TIMER_START{resolveServlet(/libs/sling/servlet/errorhandler/404.jsp)}
 313094 TIMER_END{28,resolveServlet(/libs/sling/servlet/errorhandler/404.jsp)} 
Using servlet BundledScriptServlet (/libs/sling/servlet/errorhandler/404.jsp)
 313345 TIMER_START{BundledScriptServlet 
(/libs/sling/servlet/errorhandler/404.jsp)#1}
{quote}

Here the com.adobe.cq.assetcompute.impl.servlet.InitiateUploadAssetServlet 
triggers the error handling of the Sling Engine (for whatever reason, but at 
this point it already has set the content-type to "application/json". And as a 
next step the error handler kicks in and writes the error messages with the 
content-type text/html.

We should fix this for 2 reasons:
# It is a potential XSS (the browser's JSON parser encounters HTML markup)
# In my experience the default error handling frequently focuses on the the 
"main request" only, that means it renders HTML; in some cases this error 
handling is even configured to render full fledged HTML pages which can get 
slow. This can be misused for DOS attacks, e.g. by requesting non-existing 
images.

For this reason we should make the error handling aware of the requested 
content-type and be able to register error handlers by status and content-type.







--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to