spring-projects/spring-security · error · RequestRejectedException
The request was rejected because the parameter name \"" +…
Error message
The request was rejected because the parameter name \"" + name + "\" is not allowed.
What it means
StrictHttpFirewall checks every request parameter name against the allowedParameterNames predicate. A parameter name that fails the test causes the request to be rejected with RequestRejectedException before reaching the filter chain. By default the predicate only blocks empty names, so this is usually triggered by custom configuration or names containing control characters.
Solutions
- Check the rejected parameter name in the exception and confirm the client should be sending it.
- Update the allowedParameterNames predicate via StrictHttpFirewall.setAllowedParameterNames(Predicate<String>) to permit the required name.
- Remove or fix the client-side code that sends the offending parameter name.
- Keep the default predicate (non-blank names) unless you have a strong reason to restrict further.
Example fix
// before
StrictHttpFirewall firewall = new StrictHttpFirewall();
firewall.setAllowedParameterNames(Pattern.compile("^[a-zA-Z]+$")::asMatchPredicate);
// after
StrictHttpFirewall firewall = new StrictHttpFirewall();
firewall.setAllowedParameterNames(Pattern.compile("^(?!.*[__])[\w-]+$")::asMatchPredicate); Defensive patterns
Strategy: validation
Validate before calling
// Java client-side guard
if (paramName == null || paramName.isBlank() || !paramName.chars().allMatch(c -> c > 0x20)) {
throw new IllegalArgumentException("Invalid parameter name: " + paramName);
} Try / catch
try {
return chain.filter(exchange);
} catch (RequestRejectedException e) {
log.warn("Rejected parameter name: {}", e.getMessage());
response.setStatusCode(HttpStatus.BAD_REQUEST);
return response.setComplete();
} Prevention
- Keep parameter names limited to [A-Za-z0-9_-]
- Avoid dynamically generated parameter names from user input
- Review firewall parameter-name predicates after adding new endpoints
- Log and audit rejected requests
When it happens
Trigger: A request carries a query/form parameter whose name fails StrictHttpFirewall's allowedParameterNames predicate — e.g. after configuring a restricted set of parameter names, or when the name contains non-printable characters.
Common situations: Teams restricting allowed parameter names but forgetting ones the app actually uses; clients encoding control characters into parameter names; third-party callbacks sending unexpected parameters after a firewall lockdown.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- The request was rejected because the header: \"" + name + "…
- The request was rejected because the parameter: \"" + name…
- The request was rejected because the HTTP method
- The requestURI cannot contain encoded slash. Got " +…
- The was rejected because it can only contain printable…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/a081b072d25ebe11.
Report an issue: GitHub.
Appendix: source
Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:850
}
private void validateAllowedHeaderName(String headerNames) {
if (!StrictHttpFirewall.this.allowedHeaderNames.test(headerNames)) {
throw new RequestRejectedException(
"The request was rejected because the header name \"" + headerNames + "\" is not allowed.");
}
}
private void validateAllowedHeaderValue(String name, String value) {
if (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {
throw new RequestRejectedException("The request was rejected because the header: \"" + name
+ " \" has a value \"" + value + "\" that is not allowed.");
}
}
private void validateAllowedParameterName(String name) {
if (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {
throw new RequestRejectedException(
"The request was rejected because the parameter name \"" + name + "\" is not allowed.");
}
}
private void validateAllowedParameterValue(String name, String value) {
if (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {
throw new RequestRejectedException("The request was rejected because the parameter: \"" + name
+ " \" has a value \"" + value + "\" that is not allowed.");
}
}
@Override
public void reset() {
}
};
}View on GitHub (pinned to 96852e8860)