Minor fixes stopping invalid sessions (#1850)

* Update UserAuthenticationFilter.java

* Update RequestUriUtils.java

* Update RequestUriUtils.java

* Update RequestUriUtilsTest.java
This commit is contained in:
Anthony Stirling
2024-09-08 23:06:46 +02:00
committed by GitHub
parent 6f52189ed2
commit db563c765d
3 changed files with 6 additions and 12 deletions

View File

@@ -159,7 +159,7 @@ public class UserAuthenticationFilter extends OncePerRequestFilter {
};
for (String pattern : permitAllPatterns) {
if (uri.startsWith(pattern) || uri.endsWith(".svg")) {
if (uri.startsWith(pattern) || uri.endsWith(".svg") || uri.endsWith(".png") || uri.endsWith(".ico")) {
return true;
}
}