Reading multipart request in a filter without consuming the request itself

Viewed 79

I'm stuck in a very weird problem.

I have a legacy application that I need to protect against XSS attacks. Someone before me added the classic filter/requestwrapper solution that overrides the getParameterMap and getParameterValues to clean parameter values from malicious scripts. The problem is that this works only on urlencoded forms, but when the request is from multipart-formdata forms that methods are not called, so the requestwrapper doesn't clean from that malicious code.

So I need to do the same thing but on multipart-formdata forms. After a long research I tried the following solutions:

I tried with @MultipartConfig annotation, but it works only on servlets, not filters.

I found that I can add allowCasualMultipartParsing=true in META-INF/context.xml , this allows the requestwrapper to work as with urlencoded forms but for some reason this breaks a page where the application does file uploads using a particular angular plugin, so this way is not applicable in my scenario.

So I tried to extend the filter itself, catching multipart form request and reading parameters with commons-fileupload to check for malicious scripts, but it seems to "consume" the request so the request is empty after the filter execution and the application breaks. I tried even to clone HttpRequest in order to work with a copy of the request using Gson but this caused application crash.

Do you have other ideas or suggestions? I only need to read form fields from multipart request without invalidating/consuming it. I'm stuck on this problem from weeks now.

Thank you in advance.

Best regards.

0 Answers
Related