SEC-2187: Encode query parameter names and values in return_to URL
This commit is contained in:
@@ -4,6 +4,9 @@ import static org.junit.Assert.assertEquals;
|
||||
import static org.mockito.Matchers.any;
|
||||
import static org.mockito.Mockito.*;
|
||||
|
||||
import java.net.URI;
|
||||
import java.util.Collections;
|
||||
|
||||
import javax.servlet.FilterChain;
|
||||
import javax.servlet.http.HttpServletRequest;
|
||||
import javax.servlet.http.HttpServletResponse;
|
||||
@@ -63,4 +66,35 @@ public class OpenIDAuthenticationFilterTests {
|
||||
// Filter chain shouldn't proceed
|
||||
verify(fc, never()).doFilter(any(HttpServletRequest.class), any(HttpServletResponse.class));
|
||||
}
|
||||
|
||||
/**
|
||||
* Tests that the filter encodes any query parameters on the return_to URL.
|
||||
*/
|
||||
@Test
|
||||
public void encodesUrlParameters() throws Exception {
|
||||
// Arbitrary parameter name and value that will both need to be encoded:
|
||||
String paramName = "foo&bar";
|
||||
String paramValue = "http://example.com/path?a=b&c=d";
|
||||
MockHttpServletRequest req = new MockHttpServletRequest("GET", REQUEST_PATH);
|
||||
req.addParameter(paramName, paramValue);
|
||||
filter.setReturnToUrlParameters(Collections.singleton(paramName));
|
||||
|
||||
URI returnTo = new URI(filter.buildReturnToUrl(req));
|
||||
String query = returnTo.getRawQuery();
|
||||
assertEquals(1, count(query, '='));
|
||||
assertEquals(0, count(query, '&'));
|
||||
}
|
||||
|
||||
/**
|
||||
* Counts the number of occurrences of {@code c} in {@code s}.
|
||||
*/
|
||||
private static int count(String s, char c) {
|
||||
int count = 0;
|
||||
for(char ch : s.toCharArray()) {
|
||||
if(c == ch) {
|
||||
count += 1;
|
||||
}
|
||||
}
|
||||
return count;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user