1 /* 2 * Copyright (c) 2002-2025, City of Paris 3 * All rights reserved. 4 * 5 * Redistribution and use in source and binary forms, with or without 6 * modification, are permitted provided that the following conditions 7 * are met: 8 * 9 * 1. Redistributions of source code must retain the above copyright notice 10 * and the following disclaimer. 11 * 12 * 2. Redistributions in binary form must reproduce the above copyright notice 13 * and the following disclaimer in the documentation and/or other materials 14 * provided with the distribution. 15 * 16 * 3. Neither the name of 'Mairie de Paris' nor 'Lutece' nor the names of its 17 * contributors may be used to endorse or promote products derived from 18 * this software without specific prior written permission. 19 * 20 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" 21 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 23 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR CONTRIBUTORS BE 24 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 25 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 26 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 27 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 28 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 29 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 30 * POSSIBILITY OF SUCH DAMAGE. 31 * 32 * License 1.0 33 */ 34 package fr.paris.lutece.portal.web.xss; 35 36 import javax.servlet.http.HttpServletRequest; 37 import javax.servlet.http.HttpServletRequestWrapper; 38 39 import fr.paris.lutece.portal.service.html.XSSSanitizerException; 40 import fr.paris.lutece.portal.service.html.XSSSanitizerService; 41 import fr.paris.lutece.portal.service.util.AppLogService; 42 43 public class XSSRequestWrapper extends HttpServletRequestWrapper 44 { 45 46 public XSSRequestWrapper( HttpServletRequest request ) 47 { 48 super ( request); 49 } 50 51 @Override 52 public String getParameter( String name ) 53 { 54 try 55 { 56 if ( super.getParameter( name ) == null ) 57 { 58 return null; 59 } 60 61 return XSSSanitizerService.sanitize ( super.getParameter( name ) ); 62 } 63 catch ( XSSSanitizerException e ) 64 { 65 AppLogService.error ( "XSS Sanitizer error", e ); 66 return null; 67 } 68 } 69 70 @Override 71 public String[ ] getParameterValues( String name ) 72 { 73 String[ ] values = super.getParameterValues ( name ); 74 if ( values == null ) 75 { 76 return null; 77 } 78 for ( int i = 0; i < values.length; i++ ) 79 { 80 try 81 { 82 if ( values[ i ] != null ) 83 { 84 values[ i ] = XSSSanitizerService.sanitize ( ( values[ i ] ) ); 85 } 86 } 87 catch ( XSSSanitizerException e ) 88 { 89 AppLogService.error ( "XSS Sanitizer error", e ); 90 values[ i ] = null; 91 } 92 } 93 return values; 94 } 95 }