Wraps Grizzly's HTTP request for Milton.io, sanitising header values and uploaded file field names before they reach application code. Kademi.java creates one instance per incoming request, pairing the underlying Grizzly Request with a CommentService used to strip unsafe content from header values. Overridden getters clean the referer, from-address and user-agent headers, rename uploaded file field names, and resolve the client's real IP address, preferring a trusted True-Client-IP header when present over the address reported by the underlying connection.

Extends: GrizzlyMiltonRequest


Properties

PropertyReturnsDescription
filesMap<String,FileItem>The uploaded files for this request, keyed by their form field name. The field name and, when read, the file name of each entry are cleaned via the current Formatter before being exposed to application code. The result is computed once and cached for the lifetime of the request.
fromAddressStringThe From request header, cleaned by CommentService.cleanInput to strip unsafe content before use.
refererHeaderStringThe Referer request header, cleaned by CommentService.cleanInput to strip unsafe content before use.
remoteAddrStringThe client's IP address for this request, resolved once and cached for the lifetime of the request. Prefers a trusted True-Client-IP header when it is present and holds a valid IP address, falling back to the address reported by the underlying Grizzly connection when that is itself a valid IP address.
userAgentHeaderStringThe User-Agent request header, checked for HTML markup. If the raw header value contains an angle bracket character the literal text "ERROR: Field contained HTML" is returned in place of the header, to guard against markup injection via a spoofed user agent.

Methods

getFiles()

Returns: Map<String,FileItem>

The uploaded files for this request, keyed by their form field name. The field name and, when read, the file name of each entry are cleaned via the current Formatter before being exposed to application code. The result is computed once and cached for the lifetime of the request.

getRefererHeader()

Returns: String

The Referer request header, cleaned by CommentService.cleanInput to strip unsafe content before use.

getUserAgentHeader()

Returns: String

The User-Agent request header, checked for HTML markup. If the raw header value contains an angle bracket character the literal text "ERROR: Field contained HTML" is returned in place of the header, to guard against markup injection via a spoofed user agent.

getFromAddress()

Returns: String

The From request header, cleaned by CommentService.cleanInput to strip unsafe content before use.

getRemoteAddr()

Returns: String

The client's IP address for this request, resolved once and cached for the lifetime of the request. Prefers a trusted True-Client-IP header when it is present and holds a valid IP address, falling back to the address reported by the underlying Grizzly connection when that is itself a valid IP address.

To get full access to the Kademi Hub existing customers can login here, or new customers can register here.