Deactivate shiro's blockTraversal filter

Because it breaks our branch encodings

Committed-by: Florian Scholdei <florian.scholdei@cloudogu.com>
This commit is contained in:
Eduard Heimbuch
2023-08-02 15:27:09 +02:00
parent b22722cbed
commit 8cafeefc74
2 changed files with 3 additions and 0 deletions

View File

@@ -0,0 +1,2 @@
- type: fixed
description: Deactivate Shiro's new `blockTraversal` check in their `InvalidRequestFilter`

View File

@@ -121,6 +121,7 @@ public class ScmSecurityModule extends ShiroWebModule
// do not block non ascii character,
// because this would exclude languages which are non ascii based
bindConstant().annotatedWith(Names.named("shiro.blockNonAscii")).to(false);
bindConstant().annotatedWith(Names.named("shiro.blockTraversal")).to(false);
// disable access to mustache resources
addFilterChain("/**.mustache", filterConfig(ROLES, "nobody"));