Skip to content

FISH-14642 Allow %5C (encoded backslash) in request URIs per RFC 3986 - #8432

Open
lprimak wants to merge 2 commits into
payara:mainfrom
flowlogix:add-grizzly-property-for-allow-backslash
Open

lprimak wants to merge 2 commits into
payara:mainfrom
flowlogix:add-grizzly-property-for-allow-backslash

Conversation

@lprimak

@lprimak lprimak commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

fixes #8142

Description

Requests whose path contains a percent-encoded backslash (%5C) fail with 400 Invalid URI, because Grizzly's HttpRequestURIDecoder decodes the URI before normalizing it and then rejects the resulting \. A JAX-RS path parameter carrying JSON with escaped quotes is enough to trigger it. The same application works on standalone Jersey, which never runs Grizzly's decoder.

The Grizzly side is fixed in eclipse-ee4j/glassfish-grizzly#2316 by making the check opt-in via the org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH system property: when set, a decoded backslash is kept as path data (RFC 3986) instead of being rejected or rewritten to /. A literal, unencoded \ in the request line is still rejected.

Changes

  • Set org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH=true in both domain templates (gf_template, gf_template_web), for server-config and default-config, so new domains get RFC-correct behavior out of the box.
  • CoyoteAdapter.ALLOW_BACKSLASH now also honors org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH, in addition to the legacy org.glassfish.grizzly.tcp.tomcat5.CoyoteAdapter.ALLOW_BACKSLASH, so the Tomcat-compat normalization path and Grizzly's agree on one switch.

Security note
Why this is safe to enable by default

StandardContextValve.normalize() already treats \ as a path separator when evaluating the /WEB-INF and /META-INF guard, and rejects any path that resolves above the context root. So ..%5C..%5CWEB-INF%5Cweb.xml is refused before it reaches the default servlet (verified: 404), and a backslash traversal is bounded exactly like a slash one. The decoded request path itself is not rewritten — \ still reaches the application as data. A literal, unencoded \ in the request line remains rejected by Grizzly regardless of this setting.

Existing domains

Domain templates only affect newly created domains. Upgraded installations keep the old behavior unless they opt in:

asadmin create-system-properties org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH=true

Setting the property to false (or removing it) restores the previous behavior.

Important Info

Dependency on Grizzly

This change is inert until Payara consumes a Grizzly release containing eclipse-ee4j/glassfish-grizzly#2318, which makes HttpRequestURIDecoder honor org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH. Until then, %5C is still rejected by Grizzly before the request reaches CoyoteAdapter, and the property has no effect — so merging in either order is safe, but this PR does not resolve #8142 on its own.

Testing

Reproducer at https://github.com/flowlogix/backslash-rest-reproducer
Against a JAX-RS echo resource with curl --path-as-is:

Request Before After
/echo/foo%5Cbar 400 200 foo\bar
/echo/a%5C..%5Cb 400 200 a\..\b
/echo/foo\bar (literal) 400 400
/echo/..%5C..%5CWEB-INF 400 404
/echo/../WEB-INF/web.xml 404 404

Testing Environment

Any

Documentation

TBD: The new org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH needs to be documented

Notes for the reviewers:

This PR can be merged now, and when Grizzly is updated, the changes will take effect.
There is no specific order of merging this PR vs. Grizzly PR.

…, and add it by default to new domains, so both Grizzly and Payara behavior is aligned.
@mkarg

mkarg commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Thank you, @lprimak, for this fix! You are awesome! ❤️

@Pandrex247

Copy link
Copy Markdown
Member

com.sun.enterprise.web. is an old namespace now.
My initial thought was that this should be a fish.payara, but I see that it aligns with a Grizzly property.

I can see on the Grizzly PR a similar comment has been made though suggesting it use a org.glassfish.grizzly name

@Pandrex247 Pandrex247 added the PR: CLA CLA submitted on PR by the contributor label Sep 17, 2026
@Pandrex247 Pandrex247 changed the title Allow %5C (encoded backslash) in request URIs per RFC 3986 FISH-14642 Allow %5C (encoded backslash) in request URIs per RFC 3986 Sep 17, 2026
…o `org.glassfish.grizzly.http.util.HttpRequestURIDecoder.ALLOW_BACKSLASH`
@lprimak

lprimak commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

@Pandrex247 This has been done. Got an approval for Grizzly PR as well. Thank you!

com.sun.enterprise.web. is an old namespace now. My initial thought was that this should be a fish.payara, but I see that it aligns with a Grizzly property.

I can see on the Grizzly PR a similar comment has been made though suggesting it use a org.glassfish.grizzly name

@lprimak

lprimak commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Grizzly PR has been merged!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

PR: CLA CLA submitted on PR by the contributor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug Report: %5C in path parameter produces 400 Invalid URI

3 participants