Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Sanitize collabid's before making api requests

Aperta
#157 0 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@oharsta ci sta già lavorando.

Dal 11/9/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

enhancement

AA sends the the user as a urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified to the Openconext-Invite backend, including special characters. Spring Boot (via Spring Security’s StrictHttpFirewall) blocks and rejects any request whose URL path contains a semicolon (;), throwing a RequestRejectedException. So a request containing a ; get's filterd by spring firewall in Invite, and returns an 500 error, without being logged in inviteserver.

Can we escape the paramater before sending it from AA, without changing the endpoint in invite and others?

Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: org.springframework.web.client.HttpServerErrorException$InternalServerError: 500 Internal Server Error on GET request for "https://invite.server.host/api/external/v1/aa/urn:collab:person:example.com:alskdfjlsad;f": "{"timestamp":1789114333878,"error":"Bad Request","message":"No message available","path":"/api/external/v1/aa/urn:collab:person:example.com:alskdfjlsad;f","status":500}"
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.HttpServerErrorException.create(HttpServerErrorException.java:102)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.DefaultResponseErrorHandler.handleError(DefaultResponseErrorHandler.java:189)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.DefaultResponseErrorHandler.handleError(DefaultResponseErrorHandler.java:147)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.RestTemplate.handleResponse(RestTemplate.java:953)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.RestTemplate.doExecute(RestTemplate.java:902)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.RestTemplate.execute(RestTemplate.java:801)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at org.springframework.web.client.RestTemplate.exchange(RestTemplate.java:712)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at aa.aggregators.rest.RestAttributeAggregator.doRequest(RestAttributeAggregator.java:110)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at aa.aggregators.rest.RestAttributeAggregator.fetchData(RestAttributeAggregator.java:53)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at aa.aggregators.rest.RestAttributeAggregator.aggregate(RestAttributeAggregator.java:38)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at aa.service.AttributeAggregatorService.doAggregate(AttributeAggregatorService.java:132)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at aa.service.AttributeAggregatorService.lambda$getUserAttributes$9(AttributeAggregatorService.java:114)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at java.base/java.util.concurrent.ForkJoinTask$AdaptedCallable.exec(ForkJoinTask.java:1456)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at java.base/java.util.concurrent.ForkJoinTask.doExec(ForkJoinTask.java:387)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at java.base/java.util.concurrent.ForkJoinPool$WorkQueue.topLevelExec(ForkJoinPool.java:1312)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at java.base/java.util.concurrent.ForkJoinPool.scan(ForkJoinPool.java:1843)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at java.base/java.util.concurrent.ForkJoinPool.runWorker(ForkJoinPool.java:1808)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: #011at java.base/java.util.concurrent.ForkJoinWorkerThread.run(ForkJoinWorkerThread.java:188)
Sep 11 10:12:13 docker2.test.ams.surfconext.nl aaserver[852]: 2026-09-11 08:12:13,886  WARN [ForkJoinPool-1-worker-12] a.a.rest.RestAttributeAggregator:59 - Response body found for exception, returning response body

Lingua principale
Java
Stelle
1
Fork
3
Merge medio
1g 16h
PR unite (30g)
2

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di OpenConext/OpenConext-attribute-aggregation

Tutte le issue di OpenConext/OpenConext-attribute-aggregation

Issue simili

Altre issue su Java

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.