diff --git a/oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUri.java b/oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUri.java index 39fb98d7cf..1e2430324a 100644 --- a/oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUri.java +++ b/oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUri.java @@ -27,6 +27,7 @@ * Requests. * * @author Joe Grandja + * @author Andrey Litvitski * @since 7.0 */ final class OAuth2PushedAuthorizationRequestUri { @@ -57,7 +58,7 @@ static OAuth2PushedAuthorizationRequestUri create(Instant expiresAt) { static OAuth2PushedAuthorizationRequestUri parse(String requestUri) { int stateStartIndex = REQUEST_URI_PREFIX.length(); - int expiresAtStartIndex = requestUri.indexOf(REQUEST_URI_DELIMITER) + REQUEST_URI_DELIMITER.length(); + int expiresAtStartIndex = requestUri.lastIndexOf(REQUEST_URI_DELIMITER) + REQUEST_URI_DELIMITER.length(); String state = requestUri.substring(stateStartIndex); Instant expiresAt = Instant.ofEpochMilli(Long.parseLong(requestUri.substring(expiresAtStartIndex))); return new OAuth2PushedAuthorizationRequestUri(requestUri, state, expiresAt); diff --git a/oauth2/oauth2-authorization-server/src/test/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUriTests.java b/oauth2/oauth2-authorization-server/src/test/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUriTests.java new file mode 100644 index 0000000000..a5773868cb --- /dev/null +++ b/oauth2/oauth2-authorization-server/src/test/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUriTests.java @@ -0,0 +1,44 @@ +/* + * Copyright 2004-present the original author or authors. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +package org.springframework.security.oauth2.server.authorization.authentication; + +import java.time.Instant; + +import org.junit.Test; + +import static org.assertj.core.api.Assertions.assertThat; + +/** + * Tests for {@link OAuth2PushedAuthorizationRequestUri}. + * + * @author Andrey Litvitski + */ +public class OAuth2PushedAuthorizationRequestUriTests { + + @Test + public void parseWhenStateContainsDelimiterThenParsesSuccessfully() { + String state = "xXMGJTZwzXIFL8i_DFu_EM8IeWC___frCWjpiF2q-xs="; + long epochMillis = 1781670640281L; + String requestUri = "urn:ietf:params:oauth:request_uri:" + state + "___" + epochMillis; + OAuth2PushedAuthorizationRequestUri parsedUri = OAuth2PushedAuthorizationRequestUri.parse(requestUri); + + assertThat(parsedUri.getRequestUri()).isEqualTo(requestUri); + assertThat(parsedUri.getState()).isEqualTo(state + "___" + epochMillis); + assertThat(parsedUri.getExpiresAt()).isEqualTo(Instant.ofEpochMilli(epochMillis)); + } + +}