Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
In #894, some of the nimbus dependency was removed to simplify how the tokens were handled by the library.
Unfortunately, as discovered by #922 and #937, the replacement code introduced a regression: despite the name, nimbus's
Base64Codec.decode()
was decoding them as Base64URL, not Base64. This was not caught during testing because none of the library's tests happened to produce an encoded token with characters that a Base64 decoder would not accept.This PR fixes that bug by using
Base64.getUrlDecoder()
instead ofBase64.getDecoder()
inTokenRequestExecutor.createAuthenticationResultFromOauthHttpResponse()
. In addition, it adds a unit tests showing the behavior is now correct:TestHelper.createIdToken()
to get an encoded token, and shows that token would throw anIllegalArgumentException
if passed intoBase64.getDecoder()
like was used in the old codeIllegalArgumentException
in the old code