Wraps Grizzly's HTTP request for Milton.io, sanitising header values and uploaded file field names before they reach application code. Kademi.java creates one instance per incoming request, pairing the underlying Grizzly Request with a CommentService used to strip unsafe content from header values. Overridden getters clean the referer, from-address and user-agent headers, rename uploaded file field names, and resolve the client's real IP address, preferring a trusted True-Client-IP header when present over the address reported by the underlying connection.
Extends: GrizzlyMiltonRequest
Properties
| Property | Returns | Description |
|---|---|---|
| files | Map<String,FileItem> | The uploaded files for this request, keyed by their form field name. The field name and, when read, the file name of each entry are cleaned via the current Formatter before being exposed to application code. The result is computed once and cached for the lifetime of the request. |
| fromAddress | String | The From request header, cleaned by CommentService.cleanInput to strip unsafe content before use. |
| refererHeader | String | The Referer request header, cleaned by CommentService.cleanInput to strip unsafe content before use. |
| remoteAddr | String | The client's IP address for this request, resolved once and cached for the lifetime of the request. Prefers a trusted True-Client-IP header when it is present and holds a valid IP address, falling back to the address reported by the underlying Grizzly connection when that is itself a valid IP address. |
| userAgentHeader | String | The User-Agent request header, checked for HTML markup. If the raw header value contains an angle bracket character the literal text "ERROR: Field contained HTML" is returned in place of the header, to guard against markup injection via a spoofed user agent. |
Methods
getFiles()
Returns: Map<String,FileItem>
The uploaded files for this request, keyed by their form field name. The field name and, when read, the file name of each entry are cleaned via the current Formatter before being exposed to application code. The result is computed once and cached for the lifetime of the request.
getRefererHeader()
Returns: String
The Referer request header, cleaned by CommentService.cleanInput to strip unsafe content before use.
getUserAgentHeader()
Returns: String
The User-Agent request header, checked for HTML markup. If the raw header value contains an angle bracket character the literal text "ERROR: Field contained HTML" is returned in place of the header, to guard against markup injection via a spoofed user agent.
getFromAddress()
Returns: String
The From request header, cleaned by CommentService.cleanInput to strip unsafe content before use.
getRemoteAddr()
Returns: String
The client's IP address for this request, resolved once and cached for the lifetime of the request. Prefers a trusted True-Client-IP header when it is present and holds a valid IP address, falling back to the address reported by the underlying Grizzly connection when that is itself a valid IP address.