This is an automated email from the ASF dual-hosted git repository.
joerghoh pushed a commit to branch master
in repository
https://gitbox.apache.org/repos/asf/sling-org-apache-sling-engine.git
The following commit(s) were added to refs/heads/master by this push:
new d6feb03 SLING-13365 fail by default when providing more than 10'000
parameters (#96)
d6feb03 is described below
commit d6feb03dace3dd7763aea81e8f54f14a42ac33b4
Author: Jörg Hoh <[email protected]>
AuthorDate: Tue Sep 29 12:04:48 2026 +0200
SLING-13365 fail by default when providing more than 10'000 parameters (#96)
---
.../sling/engine/impl/parameters/ParameterMap.java | 2 +-
.../RequestParameterSupportConfigurer.java | 7 +++--
.../engine/impl/SlingRequestProcessorImplTest.java | 33 ++++++++++++++++++----
.../engine/impl/parameters/ParameterMapTest.java | 4 +--
4 files changed, 34 insertions(+), 12 deletions(-)
diff --git
a/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
b/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
index 884fd5b..ca0b1ba 100644
--- a/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
+++ b/src/main/java/org/apache/sling/engine/impl/parameters/ParameterMap.java
@@ -78,7 +78,7 @@ public class ParameterMap extends LinkedHashMap<String,
RequestParameter[]> impl
// check number of parameters
if (maxParameters > -1 && this.requestParameters.size() >=
maxParameters) {
if (failOnParameterLimit) {
- throw new IllegalStateException("Too many name/value pairs,
limit is " + maxParameters);
+ throw new SlingParameterParseException("Too many name/value
pairs, limit is " + maxParameters, null);
}
LoggerFactory.getLogger(Util.class)
.warn("Too many name/value pairs, stopped processing after
" + maxParameters + " entries");
diff --git
a/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
b/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
index 7421b46..f1e6f20 100644
---
a/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
+++
b/src/main/java/org/apache/sling/engine/impl/parameters/RequestParameterSupportConfigurer.java
@@ -132,9 +132,10 @@ public class RequestParameterSupportConfigurer implements
Filter {
@AttributeDefinition(
name = "Fail on Parameter Limit",
description = "Whether to throw an exception when the maximum
number of parameters is exceeded. "
- + "If false (default), a warning is logged and
processing continues with truncated parameters. "
- + "If true, an IllegalStateException is thrown.")
- boolean sling_default_parameter_fail_on_limit() default false;
+ + "If true (default), an exception is thrown and the
request is rejected with a 400 Bad "
+ + "Request response. If false, a warning is logged and
processing continues with the "
+ + "parameter map silently truncated after the
configured limit.")
+ boolean sling_default_parameter_fail_on_limit() default true;
}
static final String PID = "org.apache.sling.engine.parameters";
diff --git
a/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
b/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
index 2a4a160..8f38a40 100644
---
a/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
+++
b/src/test/java/org/apache/sling/engine/impl/SlingRequestProcessorImplTest.java
@@ -54,7 +54,8 @@ import static org.mockito.Mockito.when;
/**
* Tests for {@link SlingRequestProcessorImpl}, in particular the
* {@code SlingParameterParseException} to HTTP 400 mapping performed in
- * {@code doProcessRequest}.
+ * {@code doProcessRequest} (regression tests for SLING-13364 and
+ * SLING-13138).
*/
public class SlingRequestProcessorImplTest {
@@ -105,11 +106,31 @@ public class SlingRequestProcessorImplTest {
* instead of propagating as a server error or being swallowed.
*/
@Test
- public void testDoProcessRequestMapsParameterParseExceptionToBadRequest()
throws Exception {
+ public void
testDoProcessRequestMapsSlingParameterParseExceptionToBadRequest() throws
Exception {
+ assertDoProcessRequestMapsExceptionToBadRequest(
+ new SlingParameterParseException("Error parsing query string",
new IllegalArgumentException("bad")),
+ "Error parsing query string");
+ }
+
+ /**
+ * {@link SlingParameterParseException} raised while servicing a request
+ * (here simulated by the resolved servlet, standing in for the parameter
+ * limit check that {@code RequestData.service} triggers indirectly via
+ * {@code ParameterMap.addParameter}) must be caught by
+ * {@code doProcessRequest} and mapped to a 400 response, instead of
+ * propagating as a server error.
+ */
+ @Test
+ public void testDoProcessRequestMapsParameterLimitExceptionToBadRequest()
throws Exception {
+ assertDoProcessRequestMapsExceptionToBadRequest(
+ new SlingParameterParseException("Too many name/value pairs,
limit is 10000", null),
+ "Too many name/value pairs");
+ }
+
+ private void assertDoProcessRequestMapsExceptionToBadRequest(
+ final RuntimeException exceptionToThrow, final String
expectedMessageFragment) throws Exception {
final Servlet servlet = mock(Servlet.class);
- doThrow(new SlingParameterParseException("Error parsing query string",
new IllegalArgumentException("bad")))
- .when(servlet)
- .service(any(ServletRequest.class),
any(ServletResponse.class));
+
doThrow(exceptionToThrow).when(servlet).service(any(ServletRequest.class),
any(ServletResponse.class));
final Resource resource = getMockedResource("/content/test");
@@ -141,7 +162,7 @@ public class SlingRequestProcessorImplTest {
verify(httpServletResponse).setStatus(SC_BAD_REQUEST);
writer.flush();
- assertTrue(writer.toString().contains("Error parsing query string"));
+ assertTrue(writer.toString().contains(expectedMessageFragment));
}
private static @NotNull Resource getMockedResource(final @NotNull String
path) {
diff --git
a/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
b/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
index a89e279..258fbfc 100644
---
a/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
+++
b/src/test/java/org/apache/sling/engine/impl/parameters/ParameterMapTest.java
@@ -76,7 +76,7 @@ public class ParameterMapTest {
assertEquals(2, pm.size());
// Should throw exception when exceeding limit
- exception.expect(IllegalStateException.class);
+ exception.expect(SlingParameterParseException.class);
exception.expectMessage("Too many name/value pairs");
exception.expectMessage("2");
pm.addParameter(createTestParameter("param3", "value3"), false);
@@ -123,7 +123,7 @@ public class ParameterMapTest {
assertEquals(5, pm.size());
// Next should fail
- exception.expect(IllegalStateException.class);
+ exception.expect(SlingParameterParseException.class);
exception.expectMessage("Too many name/value pairs");
exception.expectMessage("5");
pm.addParameter(createTestParameter("param6", "value6"), false);