Minor fixes stopping invalid sessions (#1850)
* Update UserAuthenticationFilter.java * Update RequestUriUtils.java * Update RequestUriUtils.java * Update RequestUriUtilsTest.java
This commit is contained in:
@@ -159,7 +159,7 @@ public class UserAuthenticationFilter extends OncePerRequestFilter {
|
||||
};
|
||||
|
||||
for (String pattern : permitAllPatterns) {
|
||||
if (uri.startsWith(pattern) || uri.endsWith(".svg")) {
|
||||
if (uri.startsWith(pattern) || uri.endsWith(".svg") || uri.endsWith(".png") || uri.endsWith(".ico")) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user