Uploaded image for project: 'Alfresco'
  1. Alfresco
  2. ALF-21851

Tomcat 7.0.73, 8.0.39, 8.5.7 - starting from these version throws error on illegal characters


    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Duplicate
    • Affects Version/s: Community Edition 201701 GA
    • Security Level: external (External user)
    • Labels:
    • Environment:
      Tomcat 7.0.73, 8.0.39, 8.5.7 or newer


      Starting from Tomcat 7.0.73, 8.0.39, 8.5.7 there is a stricter handling of illegal characters.
      From Tomcat change log
      " Add additional checks for valid characters to the HTTP request line parsing so invalid request lines are rejected sooner. (markt)"

      While this is not an Alfresco issue it exposes bugs present in Alfresco.
      One such issue is is in file share/src/main/webapp/components/documentlibrary/actions.js
      line 347

               var templateUrl = YAHOO.lang.substitute(Alfresco.constants.URL_SERVICECONTEXT + "components/form?itemKind={itemKind}&itemId={itemId}&destination={destination}&mode={mode}&submitType={submitType}&formId={formId}&showCancelButton=true",
                  itemKind: "node",
                  itemId: nodeRef,
                  mode: "edit",
                  submitType: "json",
                  formId: "doclib-simple-metadata"

      Here the the destination parameter is never set, and this results in a request with a parameter destination=


      that has the illegal characters{}

      This one can easily be fixed of course, but there may be other cases like this. Maybe the YAHOO.lang.substitute should be patched to remove any remaining {}-characters just to be safe (but this maybe cause other bugs).

      The above-mentioned issue is the only one I have found so far, but there may be other as testing continues.

      As for now, the solution is to stay off any version of tomcat with the mentioned versions or newer, in the long term it is a good thing as it exposes bad code.

      I listed a version affected but this applies to any version of Alfresco that use a newer version of tomcat.


          Issue Links




                • Assignee:
                  closedissues Closed Issues
                  loftux Peter Löfgren
                • Votes:
                  2 Vote for this issue
                  6 Start watching this issue


                  • Created:
                    Date of First Response:

                    Structure Helper Panel