如何在Payara Server 4.1.1.171.1中禁用HTTP OPTIONS方法?
Got it, let's figure out how to disable the OPTIONS method on your Payara Server 4.1.1.171.1—since that's what Acunetix is flagging. Here are three solid methods you can implement, depending on whether you want a global fix or app-specific control:
This method blocks OPTIONS requests across every app deployed on your Payara instance:
- Locate your Payara domain config file:
glassfish/domains/[your-domain-name]/config/domain.xml - Find the
<network-listener>node for your HTTP listener (usually namedhttp-listener-1for port 8080) - Add the
allowed-methodsattribute to the node, listing only the HTTP methods you want to allow (excludeOPTIONS):<network-listener name="http-listener-1" port="8080" protocol="http-listener-1" transport="tcp" enabled="true" allowed-methods="GET,POST,PUT,DELETE,HEAD"/> - Save the file and restart your Payara server. All OPTIONS requests will now be rejected server-wide.
If you only want to block OPTIONS for a single web application:
- Open the
WEB-INF/web.xmlfile of your target application - Add a
<security-constraint>block to deny OPTIONS requests:<security-constraint> <web-resource-collection> <web-resource-name>Block OPTIONS Method</web-resource-name> <url-pattern>/*</url-pattern> <http-method>OPTIONS</http-method> </web-resource-collection> <auth-constraint/> <!-- Empty constraint means no access allowed --> </security-constraint> - Redeploy your application. Now any OPTIONS request to this app will return a 403 Forbidden status.
For more granular control (like blocking OPTIONS only on specific paths), use a custom filter:
- Create a filter class to intercept and reject OPTIONS requests:
import javax.servlet.*; import javax.servlet.http.HttpServletRequest; import javax.servlet.http.HttpServletResponse; import java.io.IOException; public class OptionsBlockFilter implements Filter { @Override public void init(FilterConfig config) throws ServletException {} @Override public void doFilter(ServletRequest req, ServletResponse res, FilterChain chain) throws IOException, ServletException { HttpServletRequest request = (HttpServletRequest) req; HttpServletResponse response = (HttpServletResponse) res; if ("OPTIONS".equalsIgnoreCase(request.getMethod())) { response.setStatus(HttpServletResponse.SC_FORBIDDEN); return; } chain.doFilter(req, res); } @Override public void destroy() {} } - Register the filter in your app's
web.xml:<filter> <filter-name>OptionsBlockFilter</filter-name> <filter-class>com.your.package.OptionsBlockFilter</filter-class> </filter> <filter-mapping> <filter-name>OptionsBlockFilter</filter-name> <url-pattern>/*</url-pattern> <!-- Adjust this path to target specific endpoints --> </filter-mapping> - Redeploy your app. This filter will now block OPTIONS requests as configured.
How to Verify It's Working
Use curl to send an OPTIONS request to your server/app:
curl -X OPTIONS http://your-server:8080/your-app-path
If the configuration works, you should get a 403 Forbidden or 405 Method Not Allowed response.
Note: Payara 4.x is based on GlassFish 4.x, so these configurations are fully compatible with your version. Always back up config files before making changes to avoid server startup issues.
内容的提问来源于stack exchange,提问作者Vivek

