Package org.springframework.security.web.firewall
@NullMarked
package org.springframework.security.web.firewall
APIs for web security firewall support.
-
ClassDescriptionA
RequestRejectedHandlerthat delegates to several otherRequestRejectedHandlers.User's should consider usingStrictHttpFirewallbecause rather than trying to sanitize a malicious URL it rejects the malicious URL providing better security guarantees.Default implementation ofRequestRejectedHandlerthat simply rethrows the exception.Request wrapper which is returned by theHttpFirewallinterface.Interface which can be used to reject potentially dangerous requests and/or wrap them to control their behaviour.A simple implementation ofRequestRejectedHandlerthat sends an error with configurable status code.Used byFilterChainProxyto handle anRequestRejectedException.A strict implementation ofHttpFirewallthat rejects any suspicious requests with aRequestRejectedException.