aboutsummaryrefslogtreecommitdiff
path: root/src/org/traccar/web
diff options
context:
space:
mode:
authorAnton Tananaev <anton.tananaev@gmail.com>2015-12-07 09:41:42 +1300
committerAnton Tananaev <anton.tananaev@gmail.com>2015-12-07 09:41:42 +1300
commita20e996c0929bcca43e5b5595f7ec320fad3c213 (patch)
tree4c8a6f962d8c3a33468d801f7d955e368ad00115 /src/org/traccar/web
parent1c534f33c3c0c4de018b1ae223d539ac9651180d (diff)
downloadtrackermap-server-a20e996c0929bcca43e5b5595f7ec320fad3c213.tar.gz
trackermap-server-a20e996c0929bcca43e5b5595f7ec320fad3c213.tar.bz2
trackermap-server-a20e996c0929bcca43e5b5595f7ec320fad3c213.zip
Restrict CORS origin header value
Diffstat (limited to 'src/org/traccar/web')
-rw-r--r--src/org/traccar/web/BaseServlet.java2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/org/traccar/web/BaseServlet.java b/src/org/traccar/web/BaseServlet.java
index 69a073d39..8b022d556 100644
--- a/src/org/traccar/web/BaseServlet.java
+++ b/src/org/traccar/web/BaseServlet.java
@@ -56,7 +56,7 @@ public abstract class BaseServlet extends HttpServlet {
if (allowed == null) {
resp.setHeader(HttpHeaders.Names.ACCESS_CONTROL_ALLOW_ORIGIN, ALLOW_ORIGIN_VALUE);
} else if (allowed.contains(origin)) {
- String originSafe = URLEncoder.encode(origin, StandardCharsets.UTF_8.displayName());
+ String originSafe = URLEncoder.encode(origin, StandardCharsets.UTF_8.name());
resp.setHeader(HttpHeaders.Names.ACCESS_CONTROL_ALLOW_ORIGIN, originSafe);
}