enhancement
major
minor
major
minor
minor
#29669
A request with a malformed query string ("?q=50%") is answered with an "Internal error" page (HTTP 500) instead of 400
Problem
An address whose query string holds an invalid percent escape, e.g. http://localhost:30049/tl-dev/view/tickets?filter=all&q=50% typed into the browser, is answered with the full "Internal error" page, HTTP 500, and logged as an ERROR:
BadMessageException: 400: Unable to parse URI query ... TopLogicServlet.processSessionCheck
The TL Development app, snapshot build 42. The application never generates such an address itself (the view layer encodes %` as `%25); it comes from a hand-edited or truncated link.
Expected
A malformed request is a client error: HTTP 400 with a short page, logged at most as INFO or WARN without a stack trace, not an internal server error. processSessionCheck (or whatever first reads the parameters) catches Jetty's BadMessageException and answers with its status code.
Lösung
TopLogicServlet liest die Request-Parameter jetzt einmal ganz am Anfang der Verarbeitung, vor Cache-Policy und Cookie-Prüfung. Lehnt der Servlet-Container die Parameter ab (Jetty: BadMessageException beim ersten Zugriff), wird die Anfrage mit HTTP 400 und der schlichten Fehlerseite des Containers beantwortet und nur als eine WARN-Zeile ohne Stacktrace protokolliert:
WARN TopLogicServlet - Rejecting request with unparsable parameters '/tl-demo-react/view/': 400: Unable to parse URI query
Das gilt für alle Servlets auf Basis von TopLogicServlet (ViewServlet, ReactServlet, AJAXServlet, TLLayoutServlet, ...), auch für die ohne Cookie-Prüfung. Die Prüfung verwendet keine Jetty-Typen; ein Container, der fehlerhafte Parameter stillschweigend verwirft, besteht sie.