Skip to content

Commit 63f78bd

Browse files
authored
KNOX-3232: Handle pac4j cookies with "null" value (#1132)
1 parent d99996a commit 63f78bd

File tree

2 files changed

+21
-1
lines changed

2 files changed

+21
-1
lines changed

gateway-provider-security-pac4j/src/main/java/org/apache/knox/gateway/pac4j/session/KnoxSessionStore.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -105,7 +105,7 @@ public Optional<String> getSessionId(WebContext context, boolean createSession)
105105
}
106106

107107
private Object uncompressDecryptBase64(final String v) {
108-
if (v != null && !v.isEmpty()) {
108+
if (v != null && !v.isEmpty() && !"null".equals(v)) {
109109
byte[] bytes = Base64.decodeBase64(v);
110110
EncryptionResult result = EncryptionResult.fromByteArray(bytes);
111111
byte[] clear = cryptoService.decryptForCluster(this.clusterName,

gateway-provider-security-pac4j/src/test/java/org/apache/knox/gateway/pac4j/session/KnoxSessionStoreTest.java

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,18 +19,21 @@
1919

2020
import org.apache.knox.gateway.services.security.AliasService;
2121
import org.apache.knox.gateway.services.security.AliasServiceException;
22+
import org.apache.knox.gateway.services.security.CryptoService;
2223
import org.apache.knox.gateway.services.security.impl.DefaultCryptoService;
2324
import org.easymock.Capture;
2425
import org.easymock.EasyMock;
2526
import org.junit.Assert;
2627
import org.junit.Test;
28+
import org.pac4j.core.context.Cookie;
2729
import org.pac4j.core.profile.CommonProfile;
2830
import org.pac4j.core.util.Pac4jConstants;
2931
import org.pac4j.jee.context.JEEContext;
3032
import org.pac4j.saml.profile.SAML2Profile;
3133

3234
import javax.servlet.http.HttpServletResponse;
3335
import java.util.Arrays;
36+
import java.util.Collections;
3437
import java.util.HashMap;
3538
import java.util.HashSet;
3639
import java.util.Map;
@@ -44,6 +47,7 @@
4447
import static org.apache.knox.gateway.pac4j.filter.Pac4jDispatcherFilter.PAC4J_SESSION_STORE_EXCLUDE_ROLES;
4548
import static org.apache.knox.gateway.pac4j.filter.Pac4jDispatcherFilter.PAC4J_SESSION_STORE_EXCLUDE_ROLES_DEFAULT;
4649
import static org.apache.knox.gateway.pac4j.session.KnoxSessionStore.PAC4J_PASSWORD;
50+
import static org.apache.knox.gateway.pac4j.session.KnoxSessionStore.PAC4J_SESSION_PREFIX;
4751

4852
public class KnoxSessionStoreTest {
4953
private static final String CLUSTER_NAME = "knox";
@@ -158,4 +162,20 @@ public void filterConfigParamsTest()
158162
Assert.assertNotNull(samlProfile.getAttribute("https://knox.apache.org/SAML/Attributes/groups"));
159163
Assert.assertNotNull(samlProfile.getAttribute("https://knox.apache.org/SAML/Attributes/groups2"));
160164
}
165+
166+
@Test
167+
public void testNullCookieValue() throws AliasServiceException {
168+
final CryptoService cryptoService = EasyMock.createNiceMock(CryptoService.class);
169+
final Map<String, String> sessionStoreConfigs = new HashMap<>();
170+
171+
final JEEContext mockContext = EasyMock.createNiceMock(JEEContext.class);
172+
final String keyWithNullValue = "keyWithNullValue";
173+
Cookie cookie = new Cookie(PAC4J_SESSION_PREFIX + keyWithNullValue, "null");
174+
EasyMock.expect(mockContext.getRequestCookies()).andReturn(Collections.singletonList(cookie));
175+
EasyMock.replay(mockContext);
176+
177+
final KnoxSessionStore sessionStore = new KnoxSessionStore(cryptoService, CLUSTER_NAME, null, sessionStoreConfigs);
178+
Assert.assertTrue(sessionStore.get(mockContext, keyWithNullValue).isEmpty());
179+
}
180+
161181
}

0 commit comments

Comments
 (0)