Prevent manual URLS

Hello

I use JDeveloper with ADF Faces and ADF BC 11.1.1.2.

I have an unlimited flow of tasks with multiple views, including a home page. Currently, a user can manually enter a URL to bring to one of the points of view. I would now like to redirect the user to the home page, if it tries to do.

The post following 2007 describes how this can be accomplished by searching a GET a ServletFilter: Re: faces - prevent the user to manually enter the URL however, when I try to do, I find that the commandLinks in my application are also using the GET method.

I was under the impression that commandLinks were supposed to make a POST. Is there another way to tell if a URL is typed manually?

Here is the web.xml and filter code I was using to test...

Web.XML:
< filter >
< name of filter > UrlFilter < / filter-name >
> class filter < app.uiview.filters.UrlFilter < / class filter >
< / filter >
< filter mapping >
< name of filter > UrlFilter < / filter-name >
< url-pattern > /visages / * < / url-pattern >
< distributor > BEFORE < / dispatcher >
< distributor > APPLICATION < / dispatcher >
< / filter-mapping >

doFilter method in UrlFilter.java:
' Public Sub doFilter (ServletRequest request, ServletResponse response,)
FilterChain chain) throws IOException, ServletException {}
System.out.println ("\n***Method:" + ((HttpServletRequest) request) .getMethod ());
chain.doFilter (request, response);
}

Thank you
Brad

Amir/Brad,

Actually I was thinking about the possibility of using the referer in a servlet filter as well (not had time to test this out). You could very well write a servlet filter that would seek a GET request with no referer and redirection to a homepage. You may also need to be aware of GET requests model too. Another possibility would be (in your filter) to redirect the GET requests for one of your JSP resources (x) specific with the exception of the 'home page' one - you might even make it resilient against changes in your application by reading the flow of task unrelated to determine all of the 'safe' resources (which would allow GET requests) and those not safe (where you would redirect). If a GET request came across for a servlet filter resource which not was not in the unlimited workflow (as would be the case for a model), you would spend right through.

John

Tags: Java

Similar Questions

  • typing in the url of my site Web company sends to page index https in Firefox, but not IE or Chrome, and the behavior is not

    After updating Firefox to version 14.0.1 I noticed when I typed in the Web address of my business that firefox was the site https:// version when it has never done this before.

    Example, if you type in amazon.com in the URL bar, you will briefly see that firefox changes the url to https://www.amazon.com before be automatically directed to the site normal www.amazon.com .

    My site did not have a secure index page and received a message generated by the server until I discovered this problem.

    Is there a setting in Firefox to prevent the URL bar by first selecting a secure connection? This behavior occur in newer versions of I.e. or Chrome browsers on a desk.

    Any help would greatly be apprecaited

    Depending on the solution worked for me. Just put the following in the file .htaccess on your server and put your name field instead of the field below example:

  • Muse menus are fully manual or automatic?

    Is there no way to benefit from dynamically updates menus (on the page creation or change of name, etc.), but still be able to add a manual URL in the menu structure?  In other words, I want to have the menu dynamically generated, but I won't be able to add some manual URL or at least be able to add an anchor link to an existing page of Muse as a menu item.  Is this possible to ot? It's all manual or automatic all, no combination?

    Bad option.

    You want to 'Menu Options' selection in the Panel 'Options' of the Page Properties dialog box or in the context menu of a page in Plan discovered ("Include page with hyperlink", "exclude the page in the menu" or "Include page without hyperlink"). If you choose "Include page without hyperlink" then you can select the item of menu in design mode and apply any hyperlink (site page URL, anchor, external, e-mail address, etc.) by using the Hyperlink control in the Control Strip.

  • Web Form Spam

    I'm still having major issues with the form of spam on customer sites.  It seems that the forms are presented with a URL inserted into the comments field.  I implemented the captcha and recaptcha, yet the rate of spam has not declined.  I contacted the technical support of BC and they are not very useful. Can anyone recommend other solutions?  (1) delete comments for a field URL cannot be submitted with the form?  (2) use the BC askimet for forms?  (it works or overload just the customer to other functions?)  (3) use javascript to validate the comments field and prevent the URLS of the form of this area? Is it still possible?  Any help with other possible approaches would be appreciated.  Thank you!

    Be sure to check that your markup webform contains a captcha and recaptcha and also the module of {module_ccsecurity}.  But, you must also make sure that these modules are on your form in the box of BC where you installed your form.  If you just manually include these modules in your form html on your site's code, that they may not work properly.  They must also be your online form in the area of BC.  Make sure they are in both places.

    The integration of the BC Akismet works only with the comments module, I think that if your web form is not a real comments module so you can not use akismet at this time for your web form.

    There is a harder to read verstion of the {module_captchav2} which may help.  It does not change any code on your HTML web forms or update/add modules to your website forms in the admin BC... you just have to activate it by going to Site Settings > Captcha in the admin of BC and the most difficult choice to read the captcha version.

  • Help wanted with cell to daq wiring and grounding

    Hello

    I am acquiring data to a load cell using a NOR-USB-6211 OEM Board.  Under certain conditions, I see big spikes in the data that I think are caused by noise.  The DAQ card also produces an analog signal 0 - 10V for a controller of AC actuator to control its output. The current configuration is:

    Analog input: load cell Novatech wired to a Novatech "LMS" (strain gauge amplifier).  Output 0 - 10V of this amplifier is connected to terminals GND AI on the map and HAVE 0.  I use CSR configuration.

    Link to CMS Manual [url]http://www.novatechloadcells.co.uk/pdf/sgamanual.pdf[url]

    Analog output. Son connected to terminals GND AO and AO 0. Configuration of terminal CSR.

    I have attached a diagram of installation

    I understand that the GND AO and AI GND terminals are connected.  My concern is that little noise is created by AC motor controller, and it interferes with the action of the load cell. Can is this possible and if someone suggest a better configuration to avoid this situation if so? I think that at some point, one of my negative wires must be based, but I don't know which.

    Thank you very much.

    John

    OK - Thanks for the quick response. Tomorrow, I will try to acquire the load cell data using Different configuration. Perhaps this will help you reduce the noise.

    see you soon

    John

  • Yet can't overcome problem of update error 80072F8F

    Re the discussion on error 80072F8F on failure to be able to update to Vista.

    I tried all the solutions suggested in this discussion and http://support.microsoft.com/kb/929458, including the deactivation of Norton 360 and still the same error message appears.

    I stupidly had invoked the reliability of the update process and discovered that in fact no update occurred since December 10, 2008. My laptop is out of date and I can't do anything about it that Microsoft now prevents manual update, the only update authorized either through this process that now does not work. Someone at - it any other ideas? Thank you.

    123465788,

    First of all, to access a Vista command prompt you can simply type CMD in the search box, no need to create and manage more.

    Secondly, your original post said you that you did all the steps in this KB. http://support.Microsoft.com/default.aspx/KB/929458

    If possible you can double-check that you you did all the steps as he has about 4 methods to fix this problem.

    If you did all these things, I check the time and date in your BIOS and make sure that it is correct or that you do not have a low battery. If all this is correct, you must then contact your OEM, and see if there is a BIOS newer than what you use.

    However, please note. If something goes wrong with the update your BIOS you can render your motherboard not working, so I strongly recommend that you have an agent of the manufacturer of your computer support, and or the motherboard on the phone with you when you do this.

    Thank you

    Shawn

  • Capabilities with the right Protection and control of license

    Hi people,

    Just check that I understand the limits of a capabilities of clients with the power of fire with only the Protection/control.

    They will be

    1 / receive updates of poorly known ip addresses

    2 / receive updates for pre-treatment Snort rules - VDB files

    3 / be able to create manual URLS to perform a kind of Url rules in function

    4 / geolocation?

    They will not

    1 / have any possibility to send / receive file layout information

    2 / have any possibility to use Url categories

    3 / are free to set up rules to file based Malware

    Hi Evan,

    With a minimum of Protection and control, you can start the management of firepower. If the customer requires awareness of users according to a user with the license agent host Firesight will do as well as the Protection and control. You can create reports user based with the latter.

    Here's the URL and ports must be opened for the Firesight get necessary updates.

    SRU/VDB/Patch/all updates
    Ref 1 > http://www.cisco.com/c/en/us/support/docs/security/firesight-management-...

    Ref 2 > http://www.cisco.com/c/en/us/support/docs/security/firesight-management-...

    Here is the detailed information of the download server:

    Domain: support.sourcefire.com
    URL: https://support.sourcefire.com
    Port: 443/tcp (bidirectional)
    IP address: 50.19.123.95, 50.16.210.129

    Additional IP addresses that are also used by the support.sourcefire.com (in the method of Robin) are:

    54.221.210.248
    54.221.211.1
    54.221.212.60
    54.221.212.170
    54.221.212.241
    54.221.213.96
    54.221.213.209
    54.221.214.25
    54.221.214.81

    For amp
    Ref 1 > http://www.cisco.com/c/en/us/support/docs/security/firesight-management-...
    Ref 2 > http://www.cisco.com/c/en/us/support/docs/security/sourcefire-amp-applia...
    Using port 443 (bidirectional)
    Or Legacy port 32137 (out)

    For the URL filtering
    Access to the 'database.brightcloud.com' and 'service2.brightcloud.com '.
    the IP address is dynamic
    Ref 1 > http://www.cisco.com/c/en/us/support/docs/security/firesight-management-...

    Using port 443 (bidirectional)
    Using port 80 (incoming)

    For downloads of feed security intelligence:
    Access to intelligence.sourcefire.com
    The server uses the round robin scheme of IP address for the NLB, availability and fault tolerance. Therefore, IP addresses can change, and it is recommended that the firewall is configured with CNAME instead of an IP address.

    Ref 1 > http://www.cisco.com/c/en/us/support/docs/security/firesight-management-...

    Ref 2 > http://www.cisco.com/c/en/us/support/docs/security/firesight-management-...

    Using port 443 (bidirectional)
    Using port 80 (incoming)

    Kindly correct brand and rate if this helps.

    Concerning

    Jetsy

  • Auto generated issue of vanity

    Hi all

    I have a problem with vanity URL:

    First of all, I had created a model for an assettype and when I edited an asset, the URL has been generated correctly, so, I published the assets of the following environment...

    The problem came when I edited the published again active, it changes its vanity URL of self-generated NOT auto generated, so I lose the model id...

    Do you know what's happening?

    Thanks in advance!

    Hello Elena,

    When you publish an autogenerated asset with a vanity URL (for example with patter / ${name} .html), and then you change the asset (say that you change the name), the old URL becomes a manual URL and you get a new auto-generated URL.

    The old URL becomes manual so that you can decide whether to keep, delete or change to redirect to the new URL or elsewhere.

    If you change the asset and the new URL is the same, the old URL becomes even a manual URL, but the new auto-generated URL not created (because it already exists in the manual). It is the expected behavior.

    To retrieve the URL generated automatically, you can remove the manual URL and re-save the assets.

    Kind regards

    Stephan.

  • Reading out loud a little too enthusiastic

    Can we prevent reading strong mode to playback of the URL and other data not word behind the images embedded in pdf pages?

    Hi Arenal5,

    We are sorry to say that there is just no option not provided read out loud tool that can prevent read URLs and any other specific data.

    You can change a few options provided under Edit menu > Preferences > reading.

    Kind regards

    Meenakshi

  • Placement of inline text... remember to come out of the text box

    I have a chart of the family tree I made in InDesign, which is saved to a file group .indd. I initially placed this family tree in an InDesign extension document which is full of text and placed it right on top of the text and did a text wrap so that the text would be no obscure the graph.

    Now I would like to pass a separate chart placed at a fixed text graphics, so that the chart to go with the text.

    When I try either of the following workflow:

    -cut graphic, place the cursor in the text, and then paste

    or

    -remove the graphic, choose file > place, select the graphic.indd file, click the cursor in the text.

    the chart just above the slider in the form of a separate chart seems... not inline.

    No idea what could happen here?

    InDesign CS5 on Mac by the way.

    Click in the text block that contains your text then go to the history editor (file > edit in story editor or are command for the shortcut). You can see the anchor icons that indicate an anchored object? Here is a screenshot with the anchors, circled in red.

    The first is in the middle of a paragraph, and the second is in its own paragraph.

    If the object is online, it will have an icon of the anchor. If that's what you have, but you don't like the establishment, you can exit the editor and click the object on the page with the Selection tool and go to object > anchored object > Options. Here you can choose between Inline (with the possibility to change the positioning of Y if Inline), or above the line (with the possibility to change the alignment and spacing before and after space). Your other choice is personal, where you have many options. Either way, you can prevent manual positioning with a checkbox.

  • How to send the value of the prompt to an another dashboard with action link?

    Dear all,

    I find how to send the parameter to a different dashboard with the link of the action.

    URL = http://hostname/analytics/saw.dll?Dashboard & PortalPath = % 2Fusers % 2Fweblogic % 2FMartin % 20Test % 2FMartin & Page = page 1 & Action = Browse & P0 = 1 & P1 = eq & P2 = entity. "" Gen6, entity ' & P3 = % 22EntityCode % 22

    But I don't know how to send the value of the command prompt. I tried @{EntityCode}, Entity.Gen6, Entity, etc. None of them worked. They just be send as a string.

    Anyone know the solution? Thank you.

    Best regards
    Martin

    Try to do a manual URL to see if it works. Static variables are called as Valueof (variable) and presentation of variables such as @{variable}
    Discover th url below and add your variables as needed and of course override other settings.

    '' || Link | ''

  • Get all occurrences of a Word.

    Hello

    Is it possible to find all occurrences of a word in a single document using Oracle text?

    Or maybe a count of how many times a word appears in a document?

    I had a glance at the documentation and the web and don't think it is, could anyone suggest a way to do this?

    Thank you very much

    Darren.

    Hello

    You can, as Roger said to use ctx_doc.tokens. This works if you already have a clue (text) on the document. You also have the option to use ctx_doc.policy_tokens. This does not have a clue, but needs a policy. The two proceedings are with examples in the Manual: [url http://download.oracle.com/docs/cd/E11882_01/text.112/e16593/cdocpkg.htm#CEGCIDAJ] package CTX_DOC.

    Herald tiomela
    http://htendam.WordPress.com

  • shadow and table of content issues

    Hello! I have some problems with Adobe Indesign

    First:, I'm doing this effect with a text block:

    Good.jpg

    and all I can get is:Bad.jpg

    How can I do?

    In addition, I have a problem with a table of contents:

    toc.jpg

    they are not in the right order and I don't know why because the numbers are in the right order...

    Sorry for my bad English...

    Thank you very much

    Okay, I think I understand how this page is constructed. All securities seem to be inline frames, and ID seems to read the lower frame before the higher a bcause it is to the left.

    I have manged to fix this by removing the text for the title of the chapter of the inside of the frame anchored in a little test and paste in the text flow in front of the image, leaving the corner round and empty frame inline. Now, select inline frame flowing and change the anchored object > Options... from Inline or above line Custom and make sure that uncheck the prevent manual positioning. Set the X position relative to the anchor marker and uncheck the box to keep the object in the upper and lower limits of column and say OK, and then drag the frame to surround the text. Once you have properly positioned him to go back to options and tick the box to prevent any manual movement.

    Frankly, however, I think that there are probably better ways to set up the page. With just like in the subject online adds an incredible amount of complexity available and no doubt a lot of work to set the text. Maybe you can use things like points out custom or nets of paragraph rather than the boxes from the different headings. These things can be defined as part of a paragraph style and will make everything much simpler.

    I thought dividing large text image that contains all executives rooted in several shorter frames that extend to the entire width of the page might also work, but it is not so long that OCD is looking for styles that are contained in the anchored frames. That is still the position of the image that contains the text that governs the order in the table of contents.

  • How can I stop my Firefox browser to prevent click on support of families, a program that opens an email announcements on safelists, to open URLS in ads by e-mail?

    Hello fellow-users of Mozilla Firefox,.

    I have send email ads using 20 different safelists daily. To get credit for sending these ads, I click on ads email sent by other subscribers.
    Since the beginning of this year I used a click income- http://www.clickearner.net/ - to help speed up this task. Click on support of families 'captured '.
    each safelist and open e-mail each URL announced in each email. It's very fast and I didn't close each tab
    display of the URL. Credits by clicking on the URL have been added to my lists reliable accounts.

    For a week, without doing me anything at all, my click income stopped opening emails automatically as was the case for
    several months since I started using it. Click support assistance claimed that Firefox prevented the program to open the URL in a new tab whenever it extracted an advertisement by e-mail. True that, yesterday, when I watched a click back in action I've seen a pop - up from Firefox saying something like 'Firefox prevented... ". "I couldn't read the rest as the pop-up disappeared immediately. Who was the only one
    the moment I saw him.

    Right now I have to manually open each URL to see the ad and win credits. It's a very slow process, all the same when I open emails in my gmail account. There is no need for me to subscribe to click income. And it takes forever for me to earn credits to all reliable lists.

    I would appreciate it a lot if one of you people would help me overcome this glitch. I look forward to hearing from you and thank you very much in anticipation.

    Kind regards

    Tom Graciano

    You can try to disable the popup blocker in Firefox.

    "3-bar" menu button (or tools) > Options > content

    You will find a checkbox for 'block pop-up windows '. Assuming that it is checked, uncheck it.

    This is back to the desired behavior?

  • I've just updated to the latest version and now I can not manually type in the URL. I can't get to a new page if I click on a link.

    I've just updated to the latest version of Firefox 32.0.3 today and now I can not manually type in the URL. I can't get to a new page if I click on a link. I had to use - gasp - Chrome just to get to this help page!

    I tried to restart Firefox.
    I can type (not a keyboard problem), but the browser never tries to go to URL, when I hit enter

    Any ideas?

    Thanks - kept looking around and found a rec to make a reset of Firefox. This seems to have worked.

Maybe you are looking for