Skip to content

Commit

Permalink
LPS-27046 include INCLUDE dispatcher also to prevent exploit from MVC…
Browse files Browse the repository at this point in the history
…Portlet
  • Loading branch information
mikakoivisto committed May 3, 2012
1 parent 7b140b2 commit 02297c2
Showing 1 changed file with 15 additions and 1 deletion.
16 changes: 15 additions & 1 deletion portal-web/docroot/WEB-INF/liferay-web.xml
Expand Up @@ -1096,84 +1096,98 @@
<filter-name>Atom Servlet Filter</filter-name>
<url-pattern>/api/atom/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Axis Servlet Filter</filter-name>
<url-pattern>/api/axis/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>JSON Servlet Filter</filter-name>
<url-pattern>/api/json/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>JSON Web Service Servlet Filter</filter-name>
<url-pattern>/api/jsonws/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Remoting Servlet Filter</filter-name>
<url-pattern>/api/spring/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Tunnel Servlet Filter</filter-name>
<url-pattern>/api/liferay/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>WebDAV Servlet Filter</filter-name>
<url-pattern>/api/webdav/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure Atom Servlet Filter</filter-name>
<url-pattern>/api/secure/atom/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure Axis Servlet Filter</filter-name>
<url-pattern>/api/secure/axis/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure JSON Servlet Filter</filter-name>
<url-pattern>/api/secure/json/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure JSON Web Service Servlet Filter</filter-name>
<url-pattern>/api/secure/jsonws/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure Remoting Servlet Filter</filter-name>
<url-pattern>/api/secure/spring/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure Tunnel Servlet Filter</filter-name>
<url-pattern>/api/secure/liferay/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
<filter-mapping>
<filter-name>Secure WebDAV Servlet Filter</filter-name>
<url-pattern>/api/secure/webdav/*</url-pattern>
<dispatcher>FORWARD</dispatcher>
<dispatcher>INCLUDE</dispatcher>
<dispatcher>REQUEST</dispatcher>
</filter-mapping>
</web-app>
</web-app>

0 comments on commit 02297c2

Please sign in to comment.