{"id":25217379,"url":"https://github.com/valtech-ch/aem-dispatcher-filter","last_synced_at":"2026-01-19T04:32:15.197Z","repository":{"id":103667834,"uuid":"394896216","full_name":"valtech-ch/aem-dispatcher-filter","owner":"valtech-ch","description":"Dispatcher Filter Best Practices","archived":false,"fork":false,"pushed_at":"2021-09-29T10:11:28.000Z","size":49,"stargazers_count":3,"open_issues_count":0,"forks_count":1,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-04-05T09:25:51.286Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/valtech-ch.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-08-11T07:09:11.000Z","updated_at":"2023-03-20T20:47:32.000Z","dependencies_parsed_at":"2023-10-19T00:32:12.736Z","dependency_job_id":null,"html_url":"https://github.com/valtech-ch/aem-dispatcher-filter","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/valtech-ch/aem-dispatcher-filter","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/valtech-ch%2Faem-dispatcher-filter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/valtech-ch%2Faem-dispatcher-filter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/valtech-ch%2Faem-dispatcher-filter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/valtech-ch%2Faem-dispatcher-filter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/valtech-ch","download_url":"https://codeload.github.com/valtech-ch/aem-dispatcher-filter/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/valtech-ch%2Faem-dispatcher-filter/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28561840,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-19T03:31:16.861Z","status":"ssl_error","status_checked_at":"2026-01-19T03:31:15.069Z","response_time":67,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-02-10T20:13:37.048Z","updated_at":"2026-01-19T04:32:15.184Z","avatar_url":"https://github.com/valtech-ch.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# AEM Dispatcher Filter Best Practices\n\nThe AEM Dispatcher Filter best practice project was initially created together with Adobe's EMEA AEM practice to address shortcomings in the HelpX documentation, with the longer term aim of contribution to HelpX.\n\nIn general we find that dispatcher filters 'in the wild' are poorly implemented and as a result exploits that make use of crafted URLs to evade filtering are common.  Key problems are:\n\n- The OOTB dispatcher filter files on which most rulesets are based are weak. The archetype filters are designed primarily to ensure that AEM works when newly set-up and contribute little to security in their raw form.\n\n- An accepted firewall best practice of deny/allow is only loosely followed in most live dispatcher filter rulesets, that is, paraphrased:\n\n```\nDeny all\nAllow almost all\nDeny\nDeny\nDeny\netc\n```\n\nThe need for large numbers of deny rules is indicative of a poor implementation.\n\n- Developers do not always apply simple clean-coding type norms to filter configuration.  \n\n- The dispatcher filter is often an afterthought in feature development\n\n### Content\n\nThe project consists of an example dispatcher filter file and best practice documentation.\n\nThe example filter file is not suitable for direct copy'n'paste use as every client is different, however most rules can be quickly copied and adapted.  \n\n## Security is ever more important - let's get one of the the most important AEM security features right\n## Please contribute!\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvaltech-ch%2Faem-dispatcher-filter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fvaltech-ch%2Faem-dispatcher-filter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvaltech-ch%2Faem-dispatcher-filter/lists"}