mirror of
https://github.com/scm-manager/scm-manager.git
synced 2025-10-26 08:06:09 +01:00
Deactivate shiro's blockTraversal filter
Because it breaks our branch encodings Committed-by: Florian Scholdei <florian.scholdei@cloudogu.com>
This commit is contained in:
2
gradle/changelog/shiro_traversal_filter.yaml
Normal file
2
gradle/changelog/shiro_traversal_filter.yaml
Normal file
@@ -0,0 +1,2 @@
|
||||
- type: fixed
|
||||
description: Deactivate Shiro's new `blockTraversal` check in their `InvalidRequestFilter`
|
||||
@@ -121,6 +121,7 @@ public class ScmSecurityModule extends ShiroWebModule
|
||||
// do not block non ascii character,
|
||||
// because this would exclude languages which are non ascii based
|
||||
bindConstant().annotatedWith(Names.named("shiro.blockNonAscii")).to(false);
|
||||
bindConstant().annotatedWith(Names.named("shiro.blockTraversal")).to(false);
|
||||
|
||||
// disable access to mustache resources
|
||||
addFilterChain("/**.mustache", filterConfig(ROLES, "nobody"));
|
||||
|
||||
Reference in New Issue
Block a user