001/* 002 * Copyright 2025 The Apache Software Foundation. 003 * 004 * Licensed under the Apache License, Version 2.0 (the "License"); 005 * you may not use this file except in compliance with the License. 006 * You may obtain a copy of the License at 007 * 008 * http://www.apache.org/licenses/LICENSE-2.0 009 * 010 * Unless required by applicable law or agreed to in writing, software 011 * distributed under the License is distributed on an "AS IS" BASIS, 012 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 013 * See the License for the specific language governing permissions and 014 * limitations under the License. 015 */ 016package org.apache.wiki.http.filter; 017 018import jakarta.servlet.Filter; 019import jakarta.servlet.FilterChain; 020import jakarta.servlet.FilterConfig; 021import jakarta.servlet.ServletException; 022import jakarta.servlet.ServletRequest; 023import jakarta.servlet.ServletResponse; 024import org.apache.wiki.util.HttpUtil; 025 026import java.io.IOException; 027 028 029/** 030 * X-Permitted-Cross-Domain-Policies: Restricts cross-domain data loading by specific plugins, such as Flash. 031 */ 032public class CrossDomainFilter implements Filter { 033 034 private String mode = "none"; 035 036 /** {@inheritDoc} */ 037 @Override 038 public void init( final FilterConfig filterConfig ) { 039 final String configMode = FilterOperations.initValue( filterConfig, "XDomainValue", "cross-domain.value" ); 040 if( configMode != null ) { 041 mode = configMode; 042 } 043 } 044 045 /** {@inheritDoc} */ 046 @Override 047 public void doFilter( final ServletRequest request, final ServletResponse response, final FilterChain chain ) throws IOException, ServletException { 048 HttpUtil.addHeader( response,"X-Permitted-Cross-Domain-Policies", mode ); 049 chain.doFilter( request, response ); 050 } 051 052}