Spring Boot - How to sanitize path variable in interceptor

Viewed 367

I have a simple hello world app that takes a path variable and returns it:

My Controller :

@RestController
public class TestController {
  @GetMapping("/test/{user}")
  public String test2(@PathVariable String user) {
    return "Hello, " + user;
  }
}

However, this is vulnerable to attacks, if I go to the url:

http://localhost:8092/test/%3CIMG%20SRC%3Djavascript%3AqssqE6FavA0%3D7%3E

it will add it to the body:

<body>Hello, <img src="javascript:qssqE6FavA0=7"></body>

I want to add an interceptor to sanitize path variables app wide, here is what I have so far, but I'm not sure where to go from here / how to sanitize the vars and update the request:

@Component
public class XssInterceptor implements HandlerInterceptor {
  @Override
  public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws ServletException, IOException {

    Map pathVariables = (Map) request.getAttribute(HandlerMapping.URI_TEMPLATE_VARIABLES_ATTRIBUTE); 
    // = user -> <IMG SRC=javascript:qssqE6FavA0=7>

    String uri = request.getRequestURI(); 
    // = /test/%3CIMG%20SRC%3Djavascript%3AqssqE6FavA0%3D7%3E

    // how to sanitize and update the request here?

    return true;
  }
}
0 Answers
Related