Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
The "invalid request filter" blocks backslashes by default.
Add a new system property: org.apache.shiro.web.ALLOW_BACKSLASH to enable backslashes in the invalid request filter and path normalization.