Default to server_error when OAuth2Error.errorCode is null

Fixes gh-5594
This commit is contained in:
Joe Grandja
2018-07-30 12:38:36 -04:00
parent aea861e2f9
commit e243f93eed
4 changed files with 53 additions and 7 deletions

View File

@@ -28,6 +28,7 @@ import org.springframework.http.ReactiveHttpInputMessage;
import org.springframework.security.oauth2.core.OAuth2AccessToken;
import org.springframework.security.oauth2.core.OAuth2AuthenticationException;
import org.springframework.security.oauth2.core.OAuth2Error;
import org.springframework.security.oauth2.core.OAuth2ErrorCodes;
import org.springframework.security.oauth2.core.endpoint.OAuth2AccessTokenResponse;
import org.springframework.web.reactive.function.BodyExtractor;
import org.springframework.web.reactive.function.BodyExtractors;
@@ -80,11 +81,15 @@ class OAuth2AccessTokenResponseBodyExtractor
}
TokenErrorResponse tokenErrorResponse = (TokenErrorResponse) tokenResponse;
ErrorObject errorObject = tokenErrorResponse.getErrorObject();
OAuth2Error oauth2Error = new OAuth2Error(errorObject.getCode(),
errorObject.getDescription(), (errorObject.getURI() != null ?
errorObject.getURI().toString() :
null));
OAuth2Error oauth2Error;
if (errorObject == null) {
oauth2Error = new OAuth2Error(OAuth2ErrorCodes.SERVER_ERROR);
} else {
oauth2Error = new OAuth2Error(
errorObject.getCode() != null ? errorObject.getCode() : OAuth2ErrorCodes.SERVER_ERROR,
errorObject.getDescription(),
errorObject.getURI() != null ? errorObject.getURI().toString() : null);
}
return Mono.error(new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString()));
}