From cb3da28bb9bc4cb3d8717c26c6c19e4649c18834 Mon Sep 17 00:00:00 2001 From: Madhura Bhave Date: Thu, 15 Mar 2018 12:14:28 -0700 Subject: [PATCH] Enforce length > 1 for H2 and WebServices path Fixes gh-12485 --- .../autoconfigure/h2/H2ConsoleProperties.java | 6 +- .../webservices/WebServicesProperties.java | 6 +- .../h2/H2ConsolePropertiesTests.java | 59 +++++++++++++++++++ .../WebServicesPropertiesTests.java | 59 +++++++++++++++++++ 4 files changed, 126 insertions(+), 4 deletions(-) create mode 100644 spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/h2/H2ConsolePropertiesTests.java create mode 100644 spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/webservices/WebServicesPropertiesTests.java diff --git a/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/h2/H2ConsoleProperties.java b/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/h2/H2ConsoleProperties.java index c99a769681f..7650740f94d 100644 --- a/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/h2/H2ConsoleProperties.java +++ b/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/h2/H2ConsoleProperties.java @@ -48,8 +48,10 @@ public class H2ConsoleProperties { public void setPath(String path) { Assert.notNull(path, "Path must not be null"); - Assert.isTrue(path.isEmpty() || path.startsWith("/"), - "Path must start with / or be empty"); + Assert.isTrue(path.length() > 1, + "Path must have length greater than 1"); + Assert.isTrue(path.startsWith("/"), + "Path must start with '/'"); this.path = path; } diff --git a/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/webservices/WebServicesProperties.java b/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/webservices/WebServicesProperties.java index 1379170d4e9..eacf721ceb3 100644 --- a/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/webservices/WebServicesProperties.java +++ b/spring-boot-project/spring-boot-autoconfigure/src/main/java/org/springframework/boot/autoconfigure/webservices/WebServicesProperties.java @@ -45,8 +45,10 @@ public class WebServicesProperties { public void setPath(String path) { Assert.notNull(path, "Path must not be null"); - Assert.isTrue(path.isEmpty() || path.startsWith("/"), - "Path must start with / or be empty"); + Assert.isTrue(path.length() > 1, + "Path must have length greater than 1"); + Assert.isTrue(path.startsWith("/"), + "Path must start with '/'"); this.path = path; } diff --git a/spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/h2/H2ConsolePropertiesTests.java b/spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/h2/H2ConsolePropertiesTests.java new file mode 100644 index 00000000000..1588c8c9b50 --- /dev/null +++ b/spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/h2/H2ConsolePropertiesTests.java @@ -0,0 +1,59 @@ +/* + * Copyright 2012-2018 the original author or authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package org.springframework.boot.autoconfigure.h2; + +import org.junit.Rule; +import org.junit.Test; +import org.junit.rules.ExpectedException; + +/** + * Tests for {@link H2ConsoleProperties}. + * + * @author Madhura Bhave + */ +public class H2ConsolePropertiesTests { + + @Rule + public ExpectedException thrown = ExpectedException.none(); + + private H2ConsoleProperties properties; + + @Test + public void pathMustNotBeEmpty() { + this.properties = new H2ConsoleProperties(); + this.thrown.expect(IllegalArgumentException.class); + this.thrown.expectMessage("Path must have length greater than 1"); + this.properties.setPath(""); + } + + @Test + public void pathMustHaveLengthGreaterThanOne() { + this.properties = new H2ConsoleProperties(); + this.thrown.expect(IllegalArgumentException.class); + this.thrown.expectMessage("Path must have length greater than 1"); + this.properties.setPath("/"); + } + + @Test + public void customPathMustBeginWithASlash() { + this.properties = new H2ConsoleProperties(); + this.thrown.expect(IllegalArgumentException.class); + this.thrown.expectMessage("Path must start with '/'"); + this.properties.setPath("custom"); + } + +} diff --git a/spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/webservices/WebServicesPropertiesTests.java b/spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/webservices/WebServicesPropertiesTests.java new file mode 100644 index 00000000000..f7000143641 --- /dev/null +++ b/spring-boot-project/spring-boot-autoconfigure/src/test/java/org/springframework/boot/autoconfigure/webservices/WebServicesPropertiesTests.java @@ -0,0 +1,59 @@ +/* + * Copyright 2012-2018 the original author or authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package org.springframework.boot.autoconfigure.webservices; + +import org.junit.Rule; +import org.junit.Test; +import org.junit.rules.ExpectedException; + +/** + * Tests for {@link WebServicesProperties}. + * + * @author Madhura Bhave + */ +public class WebServicesPropertiesTests { + + @Rule + public ExpectedException thrown = ExpectedException.none(); + + private WebServicesProperties properties; + + @Test + public void pathMustNotBeEmpty() { + this.properties = new WebServicesProperties(); + this.thrown.expect(IllegalArgumentException.class); + this.thrown.expectMessage("Path must have length greater than 1"); + this.properties.setPath(""); + } + + @Test + public void pathMustHaveLengthGreaterThanOne() { + this.properties = new WebServicesProperties(); + this.thrown.expect(IllegalArgumentException.class); + this.thrown.expectMessage("Path must have length greater than 1"); + this.properties.setPath("/"); + } + + @Test + public void customPathMustBeginWithASlash() { + this.properties = new WebServicesProperties(); + this.thrown.expect(IllegalArgumentException.class); + this.thrown.expectMessage("Path must start with '/'"); + this.properties.setPath("custom"); + } + +}