Class ClientRedirectValidation.ClientRedirectValidator

java.lang.Object
com.broadleafcommerce.auth.server.service.ClientRedirectValidation.ClientRedirectValidator
Enclosing class:
ClientRedirectValidation

public static class ClientRedirectValidation.ClientRedirectValidator extends Object
Component responsible for validating redirection targets to protect against Open Redirect vulnerabilities.

This component provides a centralized way to validate URLs against various whitelists configured for an AuthorizedClient. It supports standard OAuth2 redirect URIs, Broadleaf-specific success whitelists, and OIDC post-logout redirect URIs.

  • Constructor Details

  • Method Details

    • sanitizeForLog

      protected String sanitizeForLog(String input)
      Sanitizes a string for safe inclusion in log files.

      This prevents Log Injection (by stripping CRLF) and Log-based XSS (by HTML encoding and truncation).

      Parameters:
      input - The raw input string.
      Returns:
      The sanitized string.
    • validatePostAuthenticationSuccessUrl

      @NonNull public ClientRedirectValidation.ClientRedirectResponse validatePostAuthenticationSuccessUrl(String url, String clientId)
      Validates if the given URL is a valid target after a successful Broadleaf-specific authentication operation (like password reset).
      Parameters:
      url - The URL to validate.
      clientId - The ID of the client to validate against.
      Returns:
      A ClientRedirectValidation.ClientRedirectResponse containing the validation status and the appropriate redirection URL.
    • validateRedirectUri

      @NonNull public ClientRedirectValidation.ClientRedirectResponse validateRedirectUri(String url, String clientId)
      Validates if the given URL is a valid target for any part of the client's authentication flow.

      This includes:

      • Standard OAuth2 redirect URIs (callbacks)
      • Broadleaf-specific success whitelists
      • OIDC post-logout redirect URIs

      Parameters:
      url - The URL to validate.
      clientId - The ID of the client to validate against.
      Returns:
      A ClientRedirectValidation.ClientRedirectResponse containing the validation status and the appropriate redirection URL.
    • validateRedirectUri

      @NonNull public ClientRedirectValidation.ClientRedirectResponse validateRedirectUri(String url, AuthorizedClient client)
      Similar to validateRedirectUri(String, String), but takes a pre-provided AuthorizedClient.
      Parameters:
      url - The URL to validate.
      client - The authorized client to validate against.
      Returns:
      A ClientRedirectValidation.ClientRedirectResponse containing the validation status and the appropriate redirection URL.
    • isValidRedirectUriInternal

      protected boolean isValidRedirectUriInternal(String url, AuthorizedClient client)
      Internal validation logic that checks the URL against standard success whitelists and resolved absolute paths.
      Parameters:
      url - The URL to validate.
      client - The authorized client to validate against.
      Returns:
      true if the URL is valid, false otherwise.
    • isMatchInResolvedWhitelists

      protected boolean isMatchInResolvedWhitelists(String url, AuthorizedClient client)
      Checks if the URL matches any of the client's resolved whitelists (success, callback, or logout).
      Parameters:
      url - The URL to validate.
      client - The authorized client to validate against.
      Returns:
      true if a match is found, false otherwise.
    • isMatch

      protected boolean isMatch(org.springframework.web.util.UriComponents requested, Set<String> whitelistedUris, AuthorizedClient client)
      Checks if the requested UriComponents match any of the provided whitelisted URIs.
      Parameters:
      requested - The parsed requested URI.
      whitelistedUris - The set of whitelisted URI strings.
      client - The authorized client context.
      Returns:
      true if a match is found, false otherwise.
    • toUriComponents

      @Nullable protected org.springframework.web.util.UriComponents toUriComponents(String uri)
      Parses a URI string into UriComponents.
      Parameters:
      uri - The URI string to parse.
      Returns:
      The parsed components, or null if parsing fails.
    • matches

      protected boolean matches(org.springframework.web.util.UriComponents requested, org.springframework.web.util.UriComponents whitelisted)
      Compares two UriComponents to determine if they represent the same target, accounting for path normalization and query parameter matching.
      Parameters:
      requested - The requested URI components.
      whitelisted - The whitelisted URI components.
      Returns:
      true if they match, false otherwise.
    • queryParamsMatch

      protected boolean queryParamsMatch(org.springframework.web.util.UriComponents requested, org.springframework.web.util.UriComponents whitelisted)
      Validates that the requested URI contains all query parameters required by the whitelist entry.
      Parameters:
      requested - The requested URI components.
      whitelisted - The whitelisted URI components.
      Returns:
      true if query parameters match, false otherwise.
    • pathsEqual

      protected boolean pathsEqual(org.springframework.web.util.UriComponents uri1, org.springframework.web.util.UriComponents uri2)
      Compares the paths of two URIs for equality, ignoring trailing slashes.
      Parameters:
      uri1 - The first URI components.
      uri2 - The second URI components.
      Returns:
      true if paths are equal, false otherwise.
    • stripTrailingSlashIfPresent

      protected String stripTrailingSlashIfPresent(String input)
      Normalizes a path string by removing a trailing slash if present.
      Parameters:
      input - The path string to normalize.
      Returns:
      The normalized path.
    • getRedirectService

      public ClientRedirectService getRedirectService()