Class ClientRedirectValidation.ClientRedirectValidator
java.lang.Object
com.broadleafcommerce.auth.server.service.ClientRedirectValidation.ClientRedirectValidator
- Enclosing class:
- ClientRedirectValidation
Component responsible for validating redirection targets to protect against Open Redirect
vulnerabilities.
This component provides a centralized way to validate URLs against various whitelists
configured for an AuthorizedClient. It supports standard OAuth2 redirect URIs,
Broadleaf-specific success whitelists, and OIDC post-logout redirect URIs.
-
Constructor Summary
ConstructorsConstructorDescriptionClientRedirectValidator(ClientRedirectService redirectService, AuthorizedClientService<AuthorizedClient> clientService) -
Method Summary
Modifier and TypeMethodDescriptionprotected booleanisMatch(org.springframework.web.util.UriComponents requested, Set<String> whitelistedUris, AuthorizedClient client) Checks if the requestedUriComponentsmatch any of the provided whitelisted URIs.protected booleanisMatchInResolvedWhitelists(String url, AuthorizedClient client) Checks if the URL matches any of the client's resolved whitelists (success, callback, or logout).protected booleanisValidRedirectUriInternal(String url, AuthorizedClient client) Internal validation logic that checks the URL against standard success whitelists and resolved absolute paths.protected booleanmatches(org.springframework.web.util.UriComponents requested, org.springframework.web.util.UriComponents whitelisted) Compares twoUriComponentsto determine if they represent the same target, accounting for path normalization and query parameter matching.protected booleanpathsEqual(org.springframework.web.util.UriComponents uri1, org.springframework.web.util.UriComponents uri2) Compares the paths of two URIs for equality, ignoring trailing slashes.protected booleanqueryParamsMatch(org.springframework.web.util.UriComponents requested, org.springframework.web.util.UriComponents whitelisted) Validates that the requested URI contains all query parameters required by the whitelist entry.protected StringsanitizeForLog(String input) Sanitizes a string for safe inclusion in log files.protected StringNormalizes a path string by removing a trailing slash if present.protected org.springframework.web.util.UriComponentstoUriComponents(String uri) Parses a URI string intoUriComponents.validatePostAuthenticationSuccessUrl(String url, String clientId) Validates if the given URL is a valid target after a successful Broadleaf-specific authentication operation (like password reset).validateRedirectUri(String url, AuthorizedClient client) Similar tovalidateRedirectUri(String, String), but takes a pre-providedAuthorizedClient.validateRedirectUri(String url, String clientId) Validates if the given URL is a valid target for any part of the client's authentication flow.
-
Constructor Details
-
ClientRedirectValidator
public ClientRedirectValidator(ClientRedirectService redirectService, AuthorizedClientService<AuthorizedClient> clientService)
-
-
Method Details
-
sanitizeForLog
Sanitizes a string for safe inclusion in log files.This prevents Log Injection (by stripping CRLF) and Log-based XSS (by HTML encoding and truncation).
- Parameters:
input- The raw input string.- Returns:
- The sanitized string.
-
validatePostAuthenticationSuccessUrl
@NonNull public ClientRedirectValidation.ClientRedirectResponse validatePostAuthenticationSuccessUrl(String url, String clientId) Validates if the given URL is a valid target after a successful Broadleaf-specific authentication operation (like password reset).- Parameters:
url- The URL to validate.clientId- The ID of the client to validate against.- Returns:
- A
ClientRedirectValidation.ClientRedirectResponsecontaining the validation status and the appropriate redirection URL.
-
validateRedirectUri
@NonNull public ClientRedirectValidation.ClientRedirectResponse validateRedirectUri(String url, String clientId) Validates if the given URL is a valid target for any part of the client's authentication flow.This includes:
- Standard OAuth2 redirect URIs (callbacks)
- Broadleaf-specific success whitelists
- OIDC post-logout redirect URIs
- Parameters:
url- The URL to validate.clientId- The ID of the client to validate against.- Returns:
- A
ClientRedirectValidation.ClientRedirectResponsecontaining the validation status and the appropriate redirection URL.
-
validateRedirectUri
@NonNull public ClientRedirectValidation.ClientRedirectResponse validateRedirectUri(String url, AuthorizedClient client) Similar tovalidateRedirectUri(String, String), but takes a pre-providedAuthorizedClient.- Parameters:
url- The URL to validate.client- The authorized client to validate against.- Returns:
- A
ClientRedirectValidation.ClientRedirectResponsecontaining the validation status and the appropriate redirection URL.
-
isValidRedirectUriInternal
Internal validation logic that checks the URL against standard success whitelists and resolved absolute paths.- Parameters:
url- The URL to validate.client- The authorized client to validate against.- Returns:
trueif the URL is valid,falseotherwise.
-
isMatchInResolvedWhitelists
Checks if the URL matches any of the client's resolved whitelists (success, callback, or logout).- Parameters:
url- The URL to validate.client- The authorized client to validate against.- Returns:
trueif a match is found,falseotherwise.
-
isMatch
protected boolean isMatch(org.springframework.web.util.UriComponents requested, Set<String> whitelistedUris, AuthorizedClient client) Checks if the requestedUriComponentsmatch any of the provided whitelisted URIs.- Parameters:
requested- The parsed requested URI.whitelistedUris- The set of whitelisted URI strings.client- The authorized client context.- Returns:
trueif a match is found,falseotherwise.
-
toUriComponents
Parses a URI string intoUriComponents.- Parameters:
uri- The URI string to parse.- Returns:
- The parsed components, or
nullif parsing fails.
-
matches
protected boolean matches(org.springframework.web.util.UriComponents requested, org.springframework.web.util.UriComponents whitelisted) Compares twoUriComponentsto determine if they represent the same target, accounting for path normalization and query parameter matching.- Parameters:
requested- The requested URI components.whitelisted- The whitelisted URI components.- Returns:
trueif they match,falseotherwise.
-
queryParamsMatch
protected boolean queryParamsMatch(org.springframework.web.util.UriComponents requested, org.springframework.web.util.UriComponents whitelisted) Validates that the requested URI contains all query parameters required by the whitelist entry.- Parameters:
requested- The requested URI components.whitelisted- The whitelisted URI components.- Returns:
trueif query parameters match,falseotherwise.
-
pathsEqual
protected boolean pathsEqual(org.springframework.web.util.UriComponents uri1, org.springframework.web.util.UriComponents uri2) Compares the paths of two URIs for equality, ignoring trailing slashes.- Parameters:
uri1- The first URI components.uri2- The second URI components.- Returns:
trueif paths are equal,falseotherwise.
-
stripTrailingSlashIfPresent
Normalizes a path string by removing a trailing slash if present.- Parameters:
input- The path string to normalize.- Returns:
- The normalized path.
-
getRedirectService
-