spring-security/oauth2/oauth2-resource-server/src
Rob Winch 6f5a443175 ServerBearerTokenAuthenticationConverter Handles Empty Tokens
Previously ServerBearerTokenAuthenticationConverter would throw an
IllegalArgumentException when the access token in a URI was empty String.
It also incorrectly provided HttpStatus.BAD_REQUEST for an empty String
access token in the headers.

This changes ServerBearerTokenAuthenticationConverter to consistently
throw a OAuth2AuthenticationException with an HttpStatus.UNAUTHORIZED

Fixes gh-7011
2019-06-24 13:57:29 -06:00
..
main/java/org/springframework/security/oauth2/server/resource ServerBearerTokenAuthenticationConverter Handles Empty Tokens 2019-06-24 13:57:29 -06:00
test/java/org/springframework/security/oauth2/server/resource ServerBearerTokenAuthenticationConverter Handles Empty Tokens 2019-06-24 13:57:29 -06:00