This is an automated email from the ASF dual-hosted git repository. markt-asf pushed a commit to branch 9.0.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 60b6a2ff137dec25be17fd5485a71b1855f29d4e Author: Mark Thomas <[email protected]> AuthorDate: Wed Sep 30 10:52:45 2026 +0100 Follow-on to 1141d547 Report error bodies for pre-auth requests as well --- .../apache/catalina/ant/AbstractCatalinaTask.java | 68 ++++++++++++++-------- 1 file changed, 43 insertions(+), 25 deletions(-) diff --git a/java/org/apache/catalina/ant/AbstractCatalinaTask.java b/java/org/apache/catalina/ant/AbstractCatalinaTask.java index 51f47b6d36..03f6b00d91 100644 --- a/java/org/apache/catalina/ant/AbstractCatalinaTask.java +++ b/java/org/apache/catalina/ant/AbstractCatalinaTask.java @@ -302,31 +302,10 @@ public abstract class AbstractCatalinaTask extends BaseRedirectorHelperTask { } } - int responseCode = hconn.getResponseCode(); - if (responseCode >= HttpURLConnection.HTTP_BAD_REQUEST) { - // For error responses, getInputStream() below would throw and - // the response body - which typically explains the error - - // would be discarded. Include its first line in the message. - String errorBody = null; - try (InputStream errorStream = hconn.getErrorStream()) { - if (errorStream != null) { - BufferedReader errorReader = new BufferedReader( - new InputStreamReader(errorStream, StandardCharsets.UTF_8)); - errorBody = errorReader.readLine(); - } - } - StringBuilder message = new StringBuilder(); - message.append("Server returned HTTP response code: "); - message.append(responseCode); - message.append(" for URL: "); - message.append(url); - message.append(command); - if (errorBody != null && !errorBody.isEmpty()) { - message.append(" - "); - message.append(errorBody); - } - throw new IOException(message.toString()); - } + // For error responses, getInputStream() below would throw and + // the response body - which typically explains the error - + // would be discarded. Include its first line in the message. + reportErrorResponse(hconn, command); // Process the response message reader = new InputStreamReader(hconn.getInputStream(), StandardCharsets.UTF_8); @@ -417,6 +396,40 @@ public abstract class AbstractCatalinaTask extends BaseRedirectorHelperTask { } + /** + * Checks the response status code and throws an IOException with the response body in the message if the status + * code is 400 or above. + * + * @param hconn The HTTP connection to be checked + * @param command The command associated with the request + * + * @throws IOException if the response has a status code of 400 or above + */ + protected void reportErrorResponse(HttpURLConnection hconn, String command) throws IOException { + int responseCode = hconn.getResponseCode(); + if (responseCode >= HttpURLConnection.HTTP_BAD_REQUEST) { + String errorBody = null; + try (InputStream errorStream = hconn.getErrorStream()) { + if (errorStream != null) { + BufferedReader errorReader = new BufferedReader( + new InputStreamReader(errorStream, StandardCharsets.UTF_8)); + errorBody = errorReader.readLine(); + } + } + StringBuilder message = new StringBuilder(); + message.append("Server returned HTTP response code: "); + message.append(responseCode); + message.append(" for URL: "); + message.append(url); + message.append(command); + if (errorBody != null && !errorBody.isEmpty()) { + message.append(" - "); + message.append(errorBody); + } + throw new IOException(message.toString()); + } + } + /* * This is a hack. We need to use streaming to avoid OOME on large uploads. We'd like to use * Authenticator.setDefault() for authentication as the JRE then provides the DIGEST client implementation. However, @@ -446,6 +459,11 @@ public abstract class AbstractCatalinaTask extends BaseRedirectorHelperTask { // Establish the connection with the server hconn.connect(); + // For error responses, getInputStream() below would throw and + // the response body - which typically explains the error - + // would be discarded. Include its first line in the message. + reportErrorResponse(hconn, " pre-authentication"); + // Swallow response message try (InputStream is = hconn.getInputStream()) { IOTools.flow(is, null); --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
