Skip to content
Snippets Groups Projects
Commit 3e406050 authored by Daniel Gerhardt's avatar Daniel Gerhardt
Browse files

Merge branch '2.x'

parents c21e5c18 d2562f45
No related merge requests found
...@@ -57,13 +57,13 @@ public class WelcomeController extends AbstractController { ...@@ -57,13 +57,13 @@ public class WelcomeController extends AbstractController {
private Properties versionInfoProperties; private Properties versionInfoProperties;
@RequestMapping(value = "/", method = RequestMethod.GET) @RequestMapping(value = "/", method = RequestMethod.GET)
public View home(final HttpServletRequest request) { public View home() {
return new RedirectView(mobileContextPath + "/", false); return new RedirectView(mobileContextPath + "/", false);
} }
@RequestMapping(value = "/", method = RequestMethod.GET, produces = "application/json") @RequestMapping(value = "/", method = RequestMethod.GET, produces = "application/json")
@ResponseBody @ResponseBody
public Map<String, Object> jsonHome(final HttpServletRequest request) { public Map<String, Object> jsonHome() {
Map<String, Object> response = new HashMap<>(); Map<String, Object> response = new HashMap<>();
Map<String, Object> version = new HashMap<>(); Map<String, Object> version = new HashMap<>();
...@@ -85,7 +85,7 @@ public class WelcomeController extends AbstractController { ...@@ -85,7 +85,7 @@ public class WelcomeController extends AbstractController {
final HttpServletRequest request final HttpServletRequest request
) { ) {
/* Block requests from the server itself to prevent DoS attacks caused by request loops */ /* Block requests from the server itself to prevent DoS attacks caused by request loops */
if ("127.0.0.1".equals(request.getRemoteAddr())) { if ("127.0.0.1".equals(request.getRemoteAddr()) || "::1".equals(request.getRemoteAddr())) {
throw new BadRequestException("Access to localhost not allowed."); throw new BadRequestException("Access to localhost not allowed.");
} }
/* Block requests to servers in private networks */ /* Block requests to servers in private networks */
......
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment