spring-projects/spring-security · error · RequestRejectedException

The request was rejected because the parameter: \"" + name…

Error message

The request was rejected because the parameter: \"" + name + " \" has a value \"" + value + "\" that is not allowed.

What it means

StrictHttpFirewall validates every request parameter value against allowedParameterValues. When a value fails the predicate, the request is rejected with RequestRejectedException before entering the filter chain. By default this blocks only non-printable ASCII, guarding against parameter-based injection payloads.

Solutions

  1. Inspect the offending parameter name/value in the exception and fix the client or form to send clean values.
  2. Adjust the predicate via StrictHttpFirewall.setAllowedParameterValues(Predicate<String>) to allow legitimate characters your app needs.
  3. Validate/sanitize user input at the source so control characters never reach the request.
  4. Avoid blanket-disabling the check; scope any relaxation narrowly to the specific parameters that need it.

Example fix

// before
firewall.setAllowedParameterValues(value -> value.matches("[\\a-zA-Z0-9]*"));
// after
firewall.setAllowedParameterValues(value -> value.chars().allMatch(c -> c >= 0x20 && c < 0x7F));
Defensive patterns

Strategy: validation

Validate before calling

// Java client-side guard
if (!value.chars().allMatch(c -> c >= 0x20 && c < 0x7F)) {
    value = URLEncoder.encode(value, StandardCharsets.UTF_8);
}

Try / catch

try {
    return chain.filter(exchange);
} catch (RequestRejectedException e) {
    log.warn("Rejected parameter value: {}", e.getMessage());
    response.setStatusCode(HttpStatus.BAD_REQUEST);
    return response.setComplete();
}

Prevention

When it happens

Trigger: A query or form parameter value contains characters rejected by the allowedParameterValues predicate — typically control characters or other content excluded by a custom predicate.

Common situations: Users pasting odd characters into forms; clients URL-encoding control bytes; teams adding a custom value predicate that is stricter than expected; payloads with binary data sent as parameter values.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/4ec4bc46b03cdcec. Report an issue: GitHub.

Appendix: source

Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:857

		}

		private void validateAllowedHeaderValue(String name, String value) {
			if (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {
				throw new RequestRejectedException("The request was rejected because the header: \"" + name
						+ " \" has a value \"" + value + "\" that is not allowed.");
			}
		}

		private void validateAllowedParameterName(String name) {
			if (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {
				throw new RequestRejectedException(
						"The request was rejected because the parameter name \"" + name + "\" is not allowed.");
			}
		}

		private void validateAllowedParameterValue(String name, String value) {
			if (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {
				throw new RequestRejectedException("The request was rejected because the parameter: \"" + name
						+ " \" has a value \"" + value + "\" that is not allowed.");
			}
		}

		@Override
		public void reset() {
		}

	};

}

View on GitHub (pinned to 96852e8860)