|
16 | 16 |
|
17 | 17 | package org.springframework.web.filter.reactive;
|
18 | 18 |
|
19 |
| -import java.net.URI; |
20 |
| -import java.util.LinkedHashSet; |
21 |
| -import java.util.Set; |
22 |
| - |
23 | 19 | import reactor.core.publisher.Mono;
|
24 | 20 |
|
25 |
| -import org.springframework.http.HttpHeaders; |
26 | 21 | import org.springframework.http.server.reactive.ServerHttpRequest;
|
27 |
| -import org.springframework.lang.Nullable; |
28 | 22 | import org.springframework.web.server.ServerWebExchange;
|
29 | 23 | import org.springframework.web.server.WebFilter;
|
30 | 24 | import org.springframework.web.server.WebFilterChain;
|
31 |
| -import org.springframework.web.util.UriComponentsBuilder; |
| 25 | +import org.springframework.web.server.adapter.ForwardedHeaderTransformer; |
32 | 26 |
|
33 | 27 | /**
|
34 |
| - * Extract values from "Forwarded" and "X-Forwarded-*" headers, and use them to |
35 |
| - * override {@link ServerHttpRequest#getURI()} to reflect the client-originated |
36 |
| - * protocol and address. |
| 28 | + * Extract values from "Forwarded" and "X-Forwarded-*" headers to override the |
| 29 | + * request URI (i.e. {@link ServerHttpRequest#getURI()}) so it reflects the |
| 30 | + * client-originated protocol and address. |
37 | 31 | *
|
38 |
| - * <p>This filter can also be used in a {@link #setRemoveOnly removeOnly} mode |
39 |
| - * where "Forwarded" and "X-Forwarded-*" headers are eliminated, and not used. |
| 32 | + * <p>Alternatively if {@link #setRemoveOnly removeOnly} is set to "true", then |
| 33 | + * "Forwarded" and "X-Forwarded-*" headers are only removed, and not used. |
40 | 34 | *
|
41 | 35 | * @author Arjen Poutsma
|
42 | 36 | * @author Rossen Stoyanchev
|
| 37 | + * @deprecated as of 5.1 this filter is deprecated in favor of using |
| 38 | + * {@link ForwardedHeaderTransformer} which can be declared as a bean with the |
| 39 | + * name "forwardedHeaderTransformer" or registered explicitly in |
| 40 | + * {@link org.springframework.web.server.adapter.WebHttpHandlerBuilder |
| 41 | + * WebHttpHandlerBuilder}. |
43 | 42 | * @since 5.0
|
44 | 43 | * @see <a href="https://tools.ietf.org/html/rfc7239">https://tools.ietf.org/html/rfc7239</a>
|
45 | 44 | */
|
46 |
| -public class ForwardedHeaderFilter implements WebFilter { |
47 |
| - |
48 |
| - static final Set<String> FORWARDED_HEADER_NAMES = new LinkedHashSet<>(5); |
49 |
| - |
50 |
| - static { |
51 |
| - FORWARDED_HEADER_NAMES.add("Forwarded"); |
52 |
| - FORWARDED_HEADER_NAMES.add("X-Forwarded-Host"); |
53 |
| - FORWARDED_HEADER_NAMES.add("X-Forwarded-Port"); |
54 |
| - FORWARDED_HEADER_NAMES.add("X-Forwarded-Proto"); |
55 |
| - FORWARDED_HEADER_NAMES.add("X-Forwarded-Prefix"); |
56 |
| - FORWARDED_HEADER_NAMES.add("X-Forwarded-Ssl"); |
57 |
| - } |
58 |
| - |
59 |
| - |
60 |
| - private boolean removeOnly; |
61 |
| - |
62 |
| - |
63 |
| - /** |
64 |
| - * Enables mode in which any "Forwarded" or "X-Forwarded-*" headers are |
65 |
| - * removed only and the information in them ignored. |
66 |
| - * @param removeOnly whether to discard and ignore forwarded headers |
67 |
| - */ |
68 |
| - public void setRemoveOnly(boolean removeOnly) { |
69 |
| - this.removeOnly = removeOnly; |
70 |
| - } |
71 |
| - |
| 45 | +@Deprecated |
| 46 | +public class ForwardedHeaderFilter extends ForwardedHeaderTransformer implements WebFilter { |
72 | 47 |
|
73 | 48 | @Override
|
74 | 49 | public Mono<Void> filter(ServerWebExchange exchange, WebFilterChain chain) {
|
75 | 50 | ServerHttpRequest request = exchange.getRequest();
|
76 |
| - if (!hasForwardedHeaders(request)) { |
77 |
| - return chain.filter(exchange); |
78 |
| - } |
79 |
| - |
80 |
| - ServerWebExchange mutatedExchange; |
81 |
| - if (this.removeOnly) { |
82 |
| - mutatedExchange = exchange.mutate().request(this::removeForwardedHeaders).build(); |
83 |
| - } |
84 |
| - else { |
85 |
| - mutatedExchange = exchange.mutate() |
86 |
| - .request(builder -> { |
87 |
| - URI uri = UriComponentsBuilder.fromHttpRequest(request).build().toUri(); |
88 |
| - builder.uri(uri); |
89 |
| - String prefix = getForwardedPrefix(request); |
90 |
| - if (prefix != null) { |
91 |
| - builder.path(prefix + uri.getPath()); |
92 |
| - builder.contextPath(prefix); |
93 |
| - } |
94 |
| - removeForwardedHeaders(builder); |
95 |
| - }) |
96 |
| - .build(); |
97 |
| - } |
98 |
| - |
99 |
| - return chain.filter(mutatedExchange); |
100 |
| - } |
101 |
| - |
102 |
| - private boolean hasForwardedHeaders(ServerHttpRequest request) { |
103 |
| - HttpHeaders headers = request.getHeaders(); |
104 |
| - for (String headerName : FORWARDED_HEADER_NAMES) { |
105 |
| - if (headers.containsKey(headerName)) { |
106 |
| - return true; |
107 |
| - } |
| 51 | + if (hasForwardedHeaders(request)) { |
| 52 | + exchange = exchange.mutate().request(apply(request)).build(); |
108 | 53 | }
|
109 |
| - return false; |
110 |
| - } |
111 |
| - |
112 |
| - @Nullable |
113 |
| - private static String getForwardedPrefix(ServerHttpRequest request) { |
114 |
| - HttpHeaders headers = request.getHeaders(); |
115 |
| - String prefix = headers.getFirst("X-Forwarded-Prefix"); |
116 |
| - if (prefix != null) { |
117 |
| - int endIndex = prefix.length(); |
118 |
| - while (endIndex > 1 && prefix.charAt(endIndex - 1) == '/') { |
119 |
| - endIndex--; |
120 |
| - } |
121 |
| - prefix = (endIndex != prefix.length() ? prefix.substring(0, endIndex) : prefix); |
122 |
| - } |
123 |
| - return prefix; |
124 |
| - } |
125 |
| - |
126 |
| - private ServerHttpRequest.Builder removeForwardedHeaders(ServerHttpRequest.Builder builder) { |
127 |
| - return builder.headers(map -> FORWARDED_HEADER_NAMES.forEach(map::remove)); |
| 54 | + return chain.filter(exchange); |
128 | 55 | }
|
129 | 56 |
|
130 | 57 | }
|
0 commit comments