|
19 | 19 | import java.io.IOException;
|
20 | 20 | import java.io.Serializable;
|
21 | 21 | import java.io.UncheckedIOException;
|
| 22 | +import java.util.Collections; |
| 23 | +import java.util.HashSet; |
22 | 24 | import java.util.Optional;
|
| 25 | +import java.util.Set; |
23 | 26 |
|
24 | 27 | import org.jsoup.Jsoup;
|
25 | 28 | import org.jsoup.nodes.DataNode;
|
@@ -66,6 +69,30 @@ public class IndexHtmlRequestHandler extends JavaScriptBootstrapHandler {
|
66 | 69 |
|
67 | 70 | private static final String SCRIPT = "script";
|
68 | 71 | private static final String SCRIPT_INITIAL = "initial";
|
| 72 | + private static final Set<String> nonHtmlFetchDests; |
| 73 | + static { |
| 74 | + // Full list at |
| 75 | + // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Sec-Fetch-Dest |
| 76 | + Set<String> dests = new HashSet<>(); |
| 77 | + dests.add("audio"); |
| 78 | + dests.add("audioworklet"); |
| 79 | + dests.add("font"); |
| 80 | + dests.add("image"); |
| 81 | + dests.add("manifest"); |
| 82 | + dests.add("paintworklet"); |
| 83 | + dests.add("script"); // NOSONAR |
| 84 | + dests.add("serviceworker"); |
| 85 | + dests.add("sharedworker"); |
| 86 | + dests.add("style"); |
| 87 | + dests.add("track"); |
| 88 | + dests.add("video"); |
| 89 | + dests.add("worker"); |
| 90 | + dests.add("xslt"); |
| 91 | + |
| 92 | + // "empty" requests are used when service worker caches / so they need |
| 93 | + // to be allowed |
| 94 | + nonHtmlFetchDests = Collections.unmodifiableSet(dests); |
| 95 | + } |
69 | 96 |
|
70 | 97 | @Override
|
71 | 98 | public boolean synchronizedHandleRequest(VaadinSession session,
|
@@ -227,8 +254,31 @@ private void includeInitialUidl(JsonObject initialJson,
|
227 | 254 |
|
228 | 255 | @Override
|
229 | 256 | protected boolean canHandleRequest(VaadinRequest request) {
|
230 |
| - return !BootstrapHandler.isFrameworkInternalRequest(request) && request |
231 |
| - .getService().getBootstrapUrlPredicate().isValidUrl(request); |
| 257 | + return isRequestForHtml(request) |
| 258 | + && !BootstrapHandler.isFrameworkInternalRequest(request) |
| 259 | + && request.getService().getBootstrapUrlPredicate() |
| 260 | + .isValidUrl(request); |
| 261 | + } |
| 262 | + |
| 263 | + /** |
| 264 | + * Checks if the request is potentially a request for a HTML page. |
| 265 | + * |
| 266 | + * @param request |
| 267 | + * the request to check |
| 268 | + * @return {@code true} if the request is potentially for HTML, |
| 269 | + * {@code false} if it is certain that it is a request for a script, |
| 270 | + * image or something else |
| 271 | + */ |
| 272 | + protected boolean isRequestForHtml(VaadinRequest request) { |
| 273 | + String fetchDest = request.getHeader("Sec-Fetch-Dest"); |
| 274 | + if (fetchDest == null) { |
| 275 | + // Old browsers do not send the header at all |
| 276 | + return true; |
| 277 | + } |
| 278 | + if (nonHtmlFetchDests.contains(fetchDest)) { |
| 279 | + return false; |
| 280 | + } |
| 281 | + return true; |
232 | 282 | }
|
233 | 283 |
|
234 | 284 | @Override
|
|
0 commit comments