spring-projects/spring-security · error · RequestRejectedException
The request was rejected because the parameter: \"" + name…
Error message
The request was rejected because the parameter: \"" + name + " \" has a value \"" + value + "\" that is not allowed.
What it means
StrictHttpFirewall validates every request parameter value against allowedParameterValues. When a value fails the predicate, the request is rejected with RequestRejectedException before entering the filter chain. By default this blocks only non-printable ASCII, guarding against parameter-based injection payloads.
Solutions
- Inspect the offending parameter name/value in the exception and fix the client or form to send clean values.
- Adjust the predicate via StrictHttpFirewall.setAllowedParameterValues(Predicate<String>) to allow legitimate characters your app needs.
- Validate/sanitize user input at the source so control characters never reach the request.
- Avoid blanket-disabling the check; scope any relaxation narrowly to the specific parameters that need it.
Example fix
// before
firewall.setAllowedParameterValues(value -> value.matches("[\\a-zA-Z0-9]*"));
// after
firewall.setAllowedParameterValues(value -> value.chars().allMatch(c -> c >= 0x20 && c < 0x7F)); Defensive patterns
Strategy: validation
Validate before calling
// Java client-side guard
if (!value.chars().allMatch(c -> c >= 0x20 && c < 0x7F)) {
value = URLEncoder.encode(value, StandardCharsets.UTF_8);
} Try / catch
try {
return chain.filter(exchange);
} catch (RequestRejectedException e) {
log.warn("Rejected parameter value: {}", e.getMessage());
response.setStatusCode(HttpStatus.BAD_REQUEST);
return response.setComplete();
} Prevention
- URL-encode all user-provided parameter values
- Sanitize form input for control characters
- Test forms with unicode/control-character inputs
- Keep custom allowedParameterValues predicates documented and reviewed
When it happens
Trigger: A query or form parameter value contains characters rejected by the allowedParameterValues predicate — typically control characters or other content excluded by a custom predicate.
Common situations: Users pasting odd characters into forms; clients URL-encoding control bytes; teams adding a custom value predicate that is stricter than expected; payloads with binary data sent as parameter values.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- The request was rejected because the header: \"" + name + "…
- The request was rejected because the parameter name \"" +…
- The request was rejected because the HTTP method
- The requestURI cannot contain encoded slash. Got " +…
- The was rejected because it can only contain printable…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/4ec4bc46b03cdcec.
Report an issue: GitHub.
Appendix: source
Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:857
}
private void validateAllowedHeaderValue(String name, String value) {
if (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {
throw new RequestRejectedException("The request was rejected because the header: \"" + name
+ " \" has a value \"" + value + "\" that is not allowed.");
}
}
private void validateAllowedParameterName(String name) {
if (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {
throw new RequestRejectedException(
"The request was rejected because the parameter name \"" + name + "\" is not allowed.");
}
}
private void validateAllowedParameterValue(String name, String value) {
if (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {
throw new RequestRejectedException("The request was rejected because the parameter: \"" + name
+ " \" has a value \"" + value + "\" that is not allowed.");
}
}
@Override
public void reset() {
}
};
}
View on GitHub (pinned to 96852e8860)