mirror of
https://github.com/spring-projects/spring-security.git
synced 2025-06-24 04:52:16 +00:00
Add Switch for Processing GET Requests
Closes gh-17099 Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
This commit is contained in:
parent
9654e51bd4
commit
8953f464fb
@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2002-2022 the original author or authors.
|
* Copyright 2002-2025 the original author or authors.
|
||||||
*
|
*
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
@ -43,6 +43,8 @@ public final class Saml2AuthenticationTokenConverter implements AuthenticationCo
|
|||||||
|
|
||||||
private Saml2AuthenticationRequestRepository<AbstractSaml2AuthenticationRequest> authenticationRequestRepository;
|
private Saml2AuthenticationRequestRepository<AbstractSaml2AuthenticationRequest> authenticationRequestRepository;
|
||||||
|
|
||||||
|
private boolean shouldConvertGetRequests = true;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Constructs a {@link Saml2AuthenticationTokenConverter} given a strategy for
|
* Constructs a {@link Saml2AuthenticationTokenConverter} given a strategy for
|
||||||
* resolving {@link RelyingPartyRegistration}s
|
* resolving {@link RelyingPartyRegistration}s
|
||||||
@ -86,16 +88,27 @@ public final class Saml2AuthenticationTokenConverter implements AuthenticationCo
|
|||||||
this.authenticationRequestRepository = authenticationRequestRepository;
|
this.authenticationRequestRepository = authenticationRequestRepository;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Use the given {@code shouldConvertGetRequests} to convert {@code GET} requests.
|
||||||
|
* Default is {@code true}.
|
||||||
|
* @param shouldConvertGetRequests the {@code shouldConvertGetRequests} to use
|
||||||
|
* @since 7.0
|
||||||
|
*/
|
||||||
|
public void setShouldConvertGetRequests(boolean shouldConvertGetRequests) {
|
||||||
|
this.shouldConvertGetRequests = shouldConvertGetRequests;
|
||||||
|
}
|
||||||
|
|
||||||
private String decode(HttpServletRequest request) {
|
private String decode(HttpServletRequest request) {
|
||||||
String encoded = request.getParameter(Saml2ParameterNames.SAML_RESPONSE);
|
String encoded = request.getParameter(Saml2ParameterNames.SAML_RESPONSE);
|
||||||
if (encoded == null) {
|
if (encoded == null) {
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
boolean isGet = HttpMethod.GET.matches(request.getMethod());
|
||||||
|
if (!this.shouldConvertGetRequests && isGet) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
try {
|
try {
|
||||||
return Saml2Utils.withEncoded(encoded)
|
return Saml2Utils.withEncoded(encoded).requireBase64(true).inflate(isGet).decode();
|
||||||
.requireBase64(true)
|
|
||||||
.inflate(HttpMethod.GET.matches(request.getMethod()))
|
|
||||||
.decode();
|
|
||||||
}
|
}
|
||||||
catch (Exception ex) {
|
catch (Exception ex) {
|
||||||
throw new Saml2AuthenticationException(new Saml2Error(Saml2ErrorCodes.INVALID_RESPONSE, ex.getMessage()),
|
throw new Saml2AuthenticationException(new Saml2Error(Saml2ErrorCodes.INVALID_RESPONSE, ex.getMessage()),
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* Copyright 2002-2021 the original author or authors.
|
* Copyright 2002-2025 the original author or authors.
|
||||||
*
|
*
|
||||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
* you may not use this file except in compliance with the License.
|
* you may not use this file except in compliance with the License.
|
||||||
@ -230,6 +230,21 @@ public class Saml2AuthenticationTokenConverterTests {
|
|||||||
.isThrownBy(() -> converter.setAuthenticationRequestRepository(null));
|
.isThrownBy(() -> converter.setAuthenticationRequestRepository(null));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
public void shouldNotConvertGetRequests() {
|
||||||
|
Saml2AuthenticationTokenConverter converter = new Saml2AuthenticationTokenConverter(
|
||||||
|
this.relyingPartyRegistrationResolver);
|
||||||
|
converter.setShouldConvertGetRequests(false);
|
||||||
|
given(this.relyingPartyRegistrationResolver.resolve(any(HttpServletRequest.class), any()))
|
||||||
|
.willReturn(this.relyingPartyRegistration);
|
||||||
|
MockHttpServletRequest request = new MockHttpServletRequest();
|
||||||
|
request.setMethod("GET");
|
||||||
|
request.setParameter(Saml2ParameterNames.SAML_RESPONSE,
|
||||||
|
Saml2Utils.samlEncode("response".getBytes(StandardCharsets.UTF_8)));
|
||||||
|
Saml2AuthenticationToken token = converter.convert(request);
|
||||||
|
assertThat(token).isNull();
|
||||||
|
}
|
||||||
|
|
||||||
private void validateSsoCircleXml(String xml) {
|
private void validateSsoCircleXml(String xml) {
|
||||||
assertThat(xml).contains("InResponseTo=\"ARQ9a73ead-7dcf-45a8-89eb-26f3c9900c36\"")
|
assertThat(xml).contains("InResponseTo=\"ARQ9a73ead-7dcf-45a8-89eb-26f3c9900c36\"")
|
||||||
.contains(" ID=\"s246d157446618e90e43fb79bdd4d9e9e19cf2c7c4\"")
|
.contains(" ID=\"s246d157446618e90e43fb79bdd4d9e9e19cf2c7c4\"")
|
||||||
|
Loading…
x
Reference in New Issue
Block a user