Class ClientRedirectValidation

java.lang.Object
com.broadleafcommerce.auth.server.service.ClientRedirectValidation

public class ClientRedirectValidation extends Object
Container class for redirection validation components used to protect against Open Redirect vulnerabilities (CWE-601).

Perceived Severity: Medium (CVSS:3.1 Base Score: 6.1 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

This class houses the domain logic, validation components, and Aspect-Oriented Programming (AOP) interceptors required to enforce a strict security policy for all redirection targets within the authentication system.

Why Open Redirect Protection Matters

Open Redirect vulnerabilities occur when an application uses a user-supplied URL as a redirection target without proper validation. In an authentication system, this is particularly dangerous as it can be leveraged for:

  • Phishing: Attackers can craft links that appear to originate from a trusted domain but redirect users to a malicious site designed to steal credentials.
  • OAuth2/OIDC Token Theft: By manipulating the redirect_uri, an attacker may attempt to leak authorization codes or access tokens to their own infrastructure.
  • Session Information Leakage: Redirection to an untrusted site can expose sensitive session state or user information via the referrer header or query parameters.

Controller Interception and Passive Redirects

We specifically target the AuthenticationController and RegistrationFormController because they represent the primary entry points for user interaction with the identity system. These controllers frequently utilize a returnTo or continue parameter to maintain user context (e.g., returning a user to their cart after login).

While ClientRedirectValidation.ClientRedirectValidationAspect.aroundSendRedirect(ProceedingJoinPoint) handles "active" redirects (HTTP 302 responses), the controller interception is critical for "passive" redirects. A passive redirect occurs when a target URL is rendered into an HTML view as part of a form action, a hidden input field, or a "Back to application" link.

Without model-level sanitization, a malicious URL could be rendered into the view (e.g., in a Thymeleaf template like fragments/login-form.html). When the user subsequently interacts with that page, their browser would perform a request to the malicious site, effectively bypassing the backend's final redirect strategy. Ensuring these model attributes are strictly whitelisted prevents attackers from embedding malicious exit points directly into the trusted authentication UI.

  • Constructor Details

    • ClientRedirectValidation

      public ClientRedirectValidation()