/* * eGov suite of products aim to improve the internal efficiency,transparency, * accountability and the service delivery of the government organizations. * * Copyright (C) <2015> eGovernments Foundation * * The updated version of eGov suite of products as by eGovernments Foundation * is available at http://www.egovernments.org * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation, either version 3 of the License, or * any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program. If not, see http://www.gnu.org/licenses/ or * http://www.gnu.org/licenses/gpl.html . * * In addition to the terms of the GPL license to be adhered to in using this * program, the following additional terms are to be complied with: * * 1) All versions of this program, verbatim or modified must carry this * Legal Notice. * * 2) Any misrepresentation of the origin of the material is prohibited. It * is required that all modified versions of this material be marked in * reasonable ways as different from the original version. * * 3) This license does not grant any rights to any user of the program * with regards to rights under trademark law for use of the trade names * or trademarks of eGovernments Foundation. * * In case of any queries, you can reach eGovernments Foundation at contact@egovernments.org. */ package org.egov.infra.web.struts.interceptors; import com.opensymphony.xwork2.ActionInvocation; import com.opensymphony.xwork2.interceptor.AbstractInterceptor; import org.apache.struts2.StrutsStatics; import javax.servlet.http.HttpServletRequest; import java.util.Iterator; import java.util.Map; import static org.egov.infra.security.utils.VirtualSanitizer.sanitize; public class TrimInterceptor extends AbstractInterceptor implements StrutsStatics { private static final long serialVersionUID = 1L; @Override public String intercept(final ActionInvocation invocation) throws Exception { // Get the action context from the invocation so we can access the // HttpServletRequest and HttpSession objects. final HttpServletRequest request = (HttpServletRequest) invocation.getInvocationContext().get(HTTP_REQUEST); Map parameters = invocation.getInvocationContext().getParameters(); parameters = this.getTrimmedParameters(request, parameters); invocation.getInvocationContext().setParameters(parameters); return invocation.invoke(); } /** * @param request * @param parameters */ public Map getTrimmedParameters(final HttpServletRequest request, final Map parameters) { for (final Iterator paramIter = parameters.entrySet().iterator(); paramIter.hasNext();) { final Map.Entry entry = (Map.Entry) paramIter.next(); final String[] values = request.getParameterValues(entry.getKey().toString()); if (values != null) { for (int i = 0; i < values.length; i++) { values[i] = sanitize(values[i].trim()); } } parameters.put(entry.getKey(), values); } return parameters; } }