The request was rejected because the URL contained a potentially malicious String "//"

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Bean
    public HttpFirewall allowUrlEncodedSlashHttpFirewall() {
        StrictHttpFirewall firewall = new StrictHttpFirewall();
        firewall.setAllowUrlEncodedSlash(true);
        firewall.setAllowUrlEncodedDoubleSlash(true);
        return firewall;
    }

    @Override
    public void configure(WebSecurity web) {
        web.httpFirewall(allowUrlEncodedSlashHttpFirewall());
    }

}

添加自定义防火墙配置即可

 

posted @ 2021-12-27 15:47  苏黎世湖畔  阅读(557)  评论(0)    收藏  举报