Refine default filtered headers for web data binding

Prior to this commit, HTTP request data binding had been improved to
filter out by default the "Priority" header in #34039.

This commit extends the set of filtered header names with:
"Accept", "Authorization", "Connection", "Cookie", "From", "Host",
"Origin", "Priority", "Range", "Referer", "Upgrade".

If an application wishes to let those header be bound, it will need to
configure the binder and replace the default header predicate by calling
`setHeaderPredicate`.

Closes gh-34182
This commit is contained in:
Brian Clozel
2025-01-07 22:11:41 +01:00
parent cd2fbb1ec5
commit c971276f34
4 changed files with 42 additions and 6 deletions
@@ -1,5 +1,5 @@
/*
* Copyright 2002-2024 the original author or authors.
* Copyright 2002-2025 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -21,6 +21,8 @@ import java.util.Map;
import jakarta.servlet.ServletRequest;
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.ValueSource;
import org.springframework.beans.MutablePropertyValues;
import org.springframework.beans.testfixture.beans.TestBean;
@@ -104,6 +106,19 @@ class ExtendedServletRequestDataBinderTests {
assertThat(target.getAge()).isEqualTo(25);
}
@ParameterizedTest
@ValueSource(strings = {"Accept", "Authorization", "Connection",
"Cookie", "From", "Host", "Origin", "Priority", "Range", "Referer", "Upgrade"})
void filteredHeaders(String headerName) {
TestBinder binder = new TestBinder();
MutablePropertyValues mpvs = new MutablePropertyValues();
request.addHeader(headerName, "u1");
binder.addBindValues(mpvs, request);
assertThat(mpvs).isEmpty();
}
@Test
void headerPredicate() {
TestBinder binder = new TestBinder();