cxf-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From cohei...@apache.org
Subject [1/7] cxf git commit: Prevent an ArrayIndexOutOfBoundsException on an empty token
Date Wed, 20 Jan 2016 15:14:25 GMT
Repository: cxf
Updated Branches:
  refs/heads/3.1.x-fixes 0f361f436 -> b856d9c43


Prevent an ArrayIndexOutOfBoundsException on an empty token


Project: http://git-wip-us.apache.org/repos/asf/cxf/repo
Commit: http://git-wip-us.apache.org/repos/asf/cxf/commit/3898f331
Tree: http://git-wip-us.apache.org/repos/asf/cxf/tree/3898f331
Diff: http://git-wip-us.apache.org/repos/asf/cxf/diff/3898f331

Branch: refs/heads/3.1.x-fixes
Commit: 3898f33155f21bc7b2e45f5fde43d3b317b9bc40
Parents: 0f361f4
Author: Colm O hEigeartaigh <coheigea@apache.org>
Authored: Wed Jan 20 11:58:10 2016 +0000
Committer: Colm O hEigeartaigh <coheigea@apache.org>
Committed: Wed Jan 20 15:02:43 2016 +0000

----------------------------------------------------------------------
 .../apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java | 3 +++
 1 file changed, 3 insertions(+)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/cxf/blob/3898f331/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java
----------------------------------------------------------------------
diff --git a/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java
b/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java
index ae34c58..3963a1f 100644
--- a/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java
+++ b/rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/OAuthRequestFilter.java
@@ -87,6 +87,9 @@ public class OAuthRequestFilter extends AbstractAccessTokenValidator
         // WWW-Authenticate with the list of supported schemes will be sent back 
         // if the scheme is not accepted
         String[] authParts = getAuthorizationParts(m);
+        if (authParts.length < 2) {
+            throw ExceptionUtils.toForbiddenException(null, null);
+        }
         String authScheme = authParts[0];
         String authSchemeData = authParts[1];
         


Mime
View raw message