重定向浏览器中的 AngularJS 页面从 Java(Spring)过滤器

huangapple go评论114阅读模式
英文:

Redirect angular js page in browser from Java (Spring) Filter

问题

  1. 我在我的Spring Boot应用程序中创建了一个SQL注入过滤器它会拦截每个请求并验证可能受到SQL注入的输入如果输入无效我想将用户重定向回登录页面使用我的代码我可以看到通过DevTools进行了内部调用但浏览器未重定向到指定页面
  2. 过滤器
  3. public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
  4. HttpServletRequest req = (HttpServletRequest) request;
  5. String url = req.getRequestURL().toString();
  6. Enumeration<String> enumeration = request.getParameterNames();
  7. while (enumeration.hasMoreElements()) {
  8. String paramName = enumeration.nextElement();
  9. String value = request.getParameter(paramName);
  10. String sqlRegex =
  11. "\\b(ALTER\\s+TABLE{0,1}|CREATE\\s+TABLE{0,1}|DELETE\\s+FROM{0,1}|DROP\\s+TABLE{0,1}|EXEC(UTE){0,1}|INSERT\\s+INTO{0,1}|MERGE\\s+INTO{0,1}|SELECT\\s[0-9a-zA-Z_*]*\\s+FROM{0,1}|UPDATE\\s[0-9a-zA-Z_]*\\s+SET{0,1}|UNION\\n+ALL{0,1})\\b";
  12. int bufferOverflowLength = 4000;
  13. if (value != null && (Pattern.compile(sqlRegex).matcher(value.toUpperCase()).find()) || value.length() >= bufferOverflowLength) {
  14. HttpServletResponse resp = (HttpServletResponse) response;
  15. String redirectUrl = req.getContextPath() + "/logout";
  16. resp.setStatus(403);
  17. resp.sendRedirect(redirectUrl);
  18. return;
  19. }
  20. }
  21. }
  1. 如何强制浏览器重定向到登出页面
  2. 更新
  3. 根据@buettner123的评论我在Angular中实现了一个httpInterceptor但仍无法拦截我的来自过滤器的请求
  4. Angular拦截器代码
  5. $httpProvider.interceptors.push(['$location', '$injector', '$q', function ($location, $injector, $q) {
  6. return {
  7. 'request': function (config) {
  8. console.log("Request intercepted");
  9. return config;
  10. },
  11. 'responseError': function (rejection) {
  12. console.log("Response Error Intercepted");
  13. return $q.reject(rejection);
  14. },
  15. 'response': function(response) {
  16. // 在成功时执行一些操作
  17. console.log('我完成了');
  18. var status = response.status;
  19. console.log(status);
  20. return response;
  21. }
  22. };
  23. }]);
英文:

I have created an SQL injection filter in my Spring Boot application that intercepts each request and validates input for a possible SQL injection. If input is invalid, then I want to redirect user back to login page. With my code, I can see internal call being made through DevTools but browser is not redirecting to specified page.

Filter

  1. public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
  2. HttpServletRequest req = (HttpServletRequest) request;
  3. String url = req.getRequestURL().toString();
  4. Enumeration&lt;String&gt; enumeration = request.getParameterNames();
  5. while (enumeration.hasMoreElements()) {
  6. String paramName = enumeration.nextElement();
  7. String value = request.getParameter(paramName);
  8. String sqlRegex =
  9. &quot;\\b(ALTER\\s+TABLE{0,1}|CREATE\\s+TABLE{0,1}|DELETE\\s+FROM{0,1}|DROP\\s+TABLE{0,1}|EXEC(UTE){0,1}|INSERT\\s+INTO{0,1}|MERGE\\s+INTO{0,1}|SELECT\\s[0-9a-zA-Z_*]*\\s+FROM{0,1}|UPDATE\\s[0-9a-zA-Z_]*\\s+SET{0,1}|UNION\\n+ALL{0,1})\\b&quot;;
  10. int bufferOverflowLength = 4000;
  11. if (value != null &amp;&amp; (Pattern.compile(sqlRegex).matcher(value.toUpperCase()).find()) || value.length() &gt;= bufferOverflowLength) {
  12. HttpServletResponse resp = (HttpServletResponse) response;
  13. String redirectUrl = req.getContextPath() + &quot;/logout&quot;;
  14. resp.setStatus(403);
  15. resp.sendRedirect(redirectUrl);
  16. return;
  17. }
  18. }

}

How can I force browser to redirect to logout page?

Update:
As per @buettner123's comment, I have implemented an httpInterceptor in Angular, but that is still unable to intercept my request from Filter.

Angular Interceptor code

  1. $httpProvider.interceptors.push([&#39;$location&#39;, &#39;$injector&#39;, &#39;$q&#39;, function ($location, $injector, $q) {
  2. return {
  3. &#39;request&#39;: function (config) {
  4. console.log(&quot;Request intercepted&quot;);
  5. return config;
  6. },
  7. &#39;responseError&#39;: function (rejection) {
  8. console.log(&quot;Response Error Intercepted&quot;);
  9. return $q.reject(rejection);
  10. },
  11. &#39;response&#39;: function(response) {
  12. // do something on success
  13. console.log(&#39;I am done&#39;);
  14. var status = response.status;
  15. console.log(status);
  16. return response;
  17. }
  18. };
  19. }]);

答案1

得分: 0

以下是您提供的内容的翻译:

在此处发布解决方案,以防其他人可能遇到相同的问题

Filter.java

  1. public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
  2. HttpServletRequest req = (HttpServletRequest) request;
  3. String url = req.getRequestURL().toString();
  4. System.out.println("url : " + url);
  5. Enumeration<String> enumeration = request.getParameterNames();
  6. while (enumeration.hasMoreElements()) {
  7. String paramName = enumeration.nextElement();
  8. String value = request.getParameter(paramName);
  9. String sqlRegex =
  10. "\\b(ALTER\\s+TABLE{0,1}|CREATE\\s+TABLE{0,1}|DELETE\\s+FROM{0,1}|DROP\\s+TABLE{0,1}|EXEC(UTE){0,1}|INSERT\\s+INTO{0,1}|MERGE\\s+INTO{0,1}|SELECT\\s[0-9a-zA-Z_*]*\\s+FROM{0,1}|UPDATE\\s[0-9a-zA-Z_]*\\s+SET{0,1}|UNION\\n+ALL{0,1})\\b";
  11. if (value != null && (Pattern.compile(sqlRegex).matcher(value.toUpperCase()).find())) {
  12. HttpSession session = req.getSession(false);
  13. if (session != null)
  14. session.invalidate();
  15. HttpServletResponse resp = (HttpServletResponse) response;
  16. resp.sendError(HttpServletResponse.SC_FORBIDDEN, "SQL注入检测到");
  17. return;
  18. }
  19. }
  20. }

main.js

  1. $httpProvider.interceptors.push(['$location', '$injector', '$q', function ($location, $injector, $q) {
  2. return {
  3. 'request': function (config) {
  4. return config;
  5. },
  6. 'responseError': function (rejection) {
  7. if (rejection.status == 403 && rejection.data.includes("SQL注入")) {
  8. console.log("禁止访问资源");
  9. window.location.href = "重定向URL";
  10. }
  11. return $q.reject(rejection);
  12. },
  13. 'response': function(response) {
  14. return response;
  15. }
  16. };
  17. }]);

确保将 JavaScript 代码放在配置元素下。

英文:

Posting the solution here in-case someone else might find themselves with the same problem

Filter.java

  1. public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain) throws IOException, ServletException {
  2. HttpServletRequest req = (HttpServletRequest) request;
  3. String url = req.getRequestURL().toString();
  4. System.out.println(&quot;url : &quot; + url);
  5. Enumeration&lt;String&gt; enumeration = request.getParameterNames();
  6. while (enumeration.hasMoreElements()) {
  7. String paramName = enumeration.nextElement();
  8. String value = request.getParameter(paramName);
  9. String sqlRegex =
  10. &quot;\\b(ALTER\\s+TABLE{0,1}|CREATE\\s+TABLE{0,1}|DELETE\\s+FROM{0,1}|DROP\\s+TABLE{0,1}|EXEC(UTE){0,1}|INSERT\\s+INTO{0,1}|MERGE\\s+INTO{0,1}|SELECT\\s[0-9a-zA-Z_*]*\\s+FROM{0,1}|UPDATE\\s[0-9a-zA-Z_]*\\s+SET{0,1}|UNION\\n+ALL{0,1})\\b&quot;;
  11. if (value != null &amp;&amp; (Pattern.compile(sqlRegex).matcher(value.toUpperCase()).find())) {
  12. HttpSession session = req.getSession(false);
  13. if (session != null)
  14. session.invalidate();
  15. HttpServletResponse resp = (HttpServletResponse) response;
  16. resp.sendError(HttpServletResponse.SC_FORBIDDEN, &quot;SQL injection detected&quot;);
  17. return;
  18. }
  19. }

}

main.js

  1. $httpProvider.interceptors.push([&#39;$location&#39;, &#39;$injector&#39;, &#39;$q&#39;, function ($location, $injector, $q) {
  2. return {
  3. &#39;request&#39;: function (config) {
  4. return config;
  5. },
  6. &#39;responseError&#39;: function (rejection) {
  7. if (rejection.status == 403 &amp;&amp; rejection.data.includes(&quot;SQL injection&quot;)) {
  8. console.log(&quot;Forbidden Resource&quot;);
  9. window.location.href=&quot;redirect url&quot;;
  10. }
  11. return $q.reject(rejection);
  12. },
  13. &#39;response&#39;: function(response) {
  14. return response;
  15. }
  16. };}]);

Make sure js code is under config element

huangapple
  • 本文由 发表于 2020年8月25日 17:41:13
  • 转载请务必保留本文链接:https://go.coder-hub.com/63576101.html
匿名

发表评论

匿名网友

:?: :razz: :sad: :evil: :!: :smile: :oops: :grin: :eek: :shock: :???: :cool: :lol: :mad: :twisted: :roll: :wink: :idea: :arrow: :neutral: :cry: :mrgreen:

确定