1
0
mirror of synced 2026-08-05 09:47:05 +00:00

Support multiple RequestRejectedHandler beans

Closes gh-10603
This commit is contained in:
Adam Ostrožlík
2021-12-11 15:27:45 +01:00
committed by Josh Cummings
parent d493598e17
commit 27cfb9c89d
4 changed files with 139 additions and 0 deletions
@@ -0,0 +1,58 @@
/*
* Copyright 2002-2022 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.security.web.firewall;
import java.io.IOException;
import java.util.Arrays;
import java.util.List;
import jakarta.servlet.ServletException;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.springframework.util.Assert;
/**
* A {@link RequestRejectedHandler} that delegates to several other
* {@link RequestRejectedHandler}s.
*
* @author Adam Ostrožlík
* @since 5.7
*/
public final class CompositeRequestRejectedHandler implements RequestRejectedHandler {
private final List<RequestRejectedHandler> requestRejectedhandlers;
/**
* Creates a new instance.
* @param requestRejectedhandlers the {@link RequestRejectedHandler} instances to
* handle {@link org.springframework.security.web.firewall.RequestRejectedException}
*/
public CompositeRequestRejectedHandler(RequestRejectedHandler... requestRejectedhandlers) {
Assert.notEmpty(requestRejectedhandlers, "requestRejectedhandlers cannot be empty");
this.requestRejectedhandlers = Arrays.asList(requestRejectedhandlers);
}
@Override
public void handle(HttpServletRequest request, HttpServletResponse response,
RequestRejectedException requestRejectedException) throws IOException, ServletException {
for (RequestRejectedHandler requestRejectedhandler : requestRejectedhandlers) {
requestRejectedhandler.handle(request, response, requestRejectedException);
}
}
}
@@ -0,0 +1,44 @@
/*
* Copyright 2002-2021 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.springframework.security.web.firewall;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import org.junit.jupiter.api.Test;
import static org.assertj.core.api.Assertions.assertThatExceptionOfType;
import static org.mockito.Mockito.mock;
public class CompositeRequestRejectedHandlerTests {
@Test
void compositeRequestRejectedHandlerRethrowsTheException() {
RequestRejectedException requestRejectedException = new RequestRejectedException("rejected");
DefaultRequestRejectedHandler sut = new DefaultRequestRejectedHandler();
CompositeRequestRejectedHandler crrh = new CompositeRequestRejectedHandler(sut);
assertThatExceptionOfType(RequestRejectedException.class).isThrownBy(() -> crrh
.handle(mock(HttpServletRequest.class), mock(HttpServletResponse.class), requestRejectedException))
.withMessage("rejected");
}
@Test
void compositeRequestRejectedHandlerForbidsEmptyHandlers() {
assertThatExceptionOfType(IllegalArgumentException.class).isThrownBy(CompositeRequestRejectedHandler::new);
}
}