[
https://issues.apache.org/jira/browse/SLING-12801?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Carsten Ziegeler updated SLING-12801:
-------------------------------------
Description:
SlingHttpServletResponseImpl.reset checks if the validation for include is
enabled and resets the response only for non-enabled cases.
For error handling, this is wrong. The ErrorFilterChain calls the reset during
the doFilter method to meet the "resetting policy" documented on:
[https://sling.apache.org/documentation/the-sling-engine/errorhandling.html]
was:
SlingHttpServletResponseImpl.reset checks if the validation is enabled and
resets the response only for non-enabled cases.
For edge cases like error handling, this is wrong. The ErrorFilterChain calls
the reset during the doFilter method to meet the "resetting policy" documented
on:
[https://sling.apache.org/documentation/the-sling-engine/errorhandling.html]
Resetting the Response
{*}Before an ErrorHandler is invoked by the Sling Engine, the response is
resetted{*}. *This removes all headers* and potentially written content. If the
response can't be reset, e.g. when it is already partially committed to the
client, no ErrorHandler will be invoked. In this case the response will be
committed as-is.As the response is reset by Sling Engine, an ErrorHandler must
not reset the response again. Especially as there might be error filters being
invoked before the ErrorHandler.
> Error handler does not reset the response during include
> --------------------------------------------------------
>
> Key: SLING-12801
> URL: https://issues.apache.org/jira/browse/SLING-12801
> Project: Sling
> Issue Type: Bug
> Components: Engine
> Affects Versions: Engine 3.0.0, Engine 2.16.2
> Reporter: Remo Liechti
> Priority: Major
>
> SlingHttpServletResponseImpl.reset checks if the validation for include is
> enabled and resets the response only for non-enabled cases.
> For error handling, this is wrong. The ErrorFilterChain calls the reset
> during the doFilter method to meet the "resetting policy" documented on:
> [https://sling.apache.org/documentation/the-sling-engine/errorhandling.html]
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)