You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security4.2.4升级后SAML中URL含分号触发RequestRejectedException怎么办?

解决Spring Security 4.2.4中含分号URL及SAML场景下的RequestRejectedException问题

问题根源

Spring Security 4.2.x版本起默认启用了StrictHttpFirewall组件,它会将URL中的分号(;)判定为潜在恶意字符(可能被用于路径参数篡改类攻击),直接拦截请求并抛出RequestRejectedException。

普通Web场景解决方案

我们可以通过自定义防火墙规则,允许URL中包含分号来解决这个问题:

  1. 创建自定义StrictHttpFirewall配置Bean:
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.web.firewall.StrictHttpFirewall;

@Configuration
public class FirewallConfig {

    @Bean
    public StrictHttpFirewall customHttpFirewall() {
        StrictHttpFirewall firewall = new StrictHttpFirewall();
        firewall.setAllowSemicolon(true); // 开启允许分号的规则
        // 若业务需要,还可开启其他被默认拦截的字符,比如反斜杠、百分号等
        // firewall.setAllowBackSlash(true);
        // firewall.setAllowPercentEncoded(true);
        return firewall;
    }
}
  1. 在Spring Security主配置类中应用这个自定义防火墙:
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.config.annotation.web.builders.WebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private StrictHttpFirewall customHttpFirewall;

    @Override
    public void configure(WebSecurity web) throws Exception {
        web.httpFirewall(customHttpFirewall);
        // 其他WebSecurity配置...
    }

    // 此处添加HttpSecurity相关配置(如授权、认证规则)
}

SAML场景额外适配

如果项目使用Spring SAML实现单点登录,需要确保SAML相关的过滤器链也能应用自定义防火墙规则,避免SAML流程中触发同样的异常:

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.saml.metadata.MetadataGeneratorFilter;
import org.springframework.security.web.context.SecurityContextPersistenceFilter;
import org.springframework.security.web.firewall.StrictHttpFirewall;

public class SAMLSecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private StrictHttpFirewall customHttpFirewall;

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .httpFirewall(customHttpFirewall) // 为SAML的请求链绑定自定义防火墙
            .authorizeRequests()
            .antMatchers("/saml/**").permitAll()
            // 其他SAML授权规则...
            .and()
            .addFilterBefore(metadataGeneratorFilter(), SecurityContextPersistenceFilter.class);
            // 其他SAML过滤器配置...
    }

    // 此处添加SAML所需的其他Bean(如MetadataGeneratorFilter等)
}

安全提示

开启允许分号会降低防火墙的防护强度,建议仅在业务确实需要的场景下启用,同时搭配严格的输入校验、参数合法性验证等措施,尽可能降低安全风险。

内容的提问来源于stack exchange,提问作者Vanitha V

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:53:41