Skip to main content
adivj95
Level 2
October 16, 2023
Resuelto

Dispatcher : Asset Path security issue

  • October 16, 2023
  • 1 respuesta
  • 601 visualizaciones

Hi community

 

I want to write a generic rule to deny this type of path

/content/dam/myproject/asset.jpg/.4.json

/content/dam/myproject/asset.xls/.4.json


I already have this rule in dispatcher and its not applying for this paths

/0081
{
/type "deny"
/selectors '((sys|doc)view|query|[0-9-]+)'
/extension '(json|xml|css|js|xls)'
}
# Deny content grabbing for /content
/0082
{
/type "deny"
/path "/content"
/selectors '(feed|rss|pages|languages|blueprint|infinity|tidy)'
/extension '(json|xml|html|css|js)'
}

Please help

Este tema ha sido cerrado para respuestas.
Mejor respuesta de Mahedi_Sabuj

Here "/.4.json" is considered a suffix, not a selector. You need to deny suffix from the dispatcher. You can check below example for a reference: 

# Block the use of all suffixes on any resource under /content /0160 { /type "deny" /url "/content*" /suffix "*" }

For more information about what part of the request line each of these elements references, see the Sling URL Decomposition wiki page.

 

 

1 respuesta

Mahedi_Sabuj
Community Advisor
Mahedi_SabujCommunity AdvisorRespuesta
Community Advisor
October 16, 2023

Here "/.4.json" is considered a suffix, not a selector. You need to deny suffix from the dispatcher. You can check below example for a reference: 

# Block the use of all suffixes on any resource under /content /0160 { /type "deny" /url "/content*" /suffix "*" }

For more information about what part of the request line each of these elements references, see the Sling URL Decomposition wiki page.

 

 

Mahedi Sabuj