Out-of-range NumericDate claims can throw unchecked DateTimeException during verification
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 72/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Tranquilla
- Stack tecnologico
- java
- Ambito
- authentication, security
Direzione di ricerca
Inizia da JWTVerifier.verify(String), quindi leggi JWTParser.parsePayload(...) e PayloadDeserializer.getInstantFromSeconds(...) nei file indicati di lib/src/main/java/com/auth0/jwt. Esegui la riproduzione Maven fornita con il valore exp fuori intervallo e verifica che exp, nbf e iat non sfuggano più come DateTimeException, ma raggiungano il confine delle eccezioni della libreria per i token non validi.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Checklist
- I have looked into the Readme and Examples, and have not found a suitable solution or answer.
- I have looked into the API documentation and have not found a suitable solution or answer.
- I have searched the issues and have not found a suitable solution or answer.
- I have searched the Auth0 Community forums and have not found a suitable solution or answer.
- I agree to the terms within the Auth0 Code of Conduct.
Description
JWTVerifier.verify(String) can throw java.time.DateTimeException when a registered NumericDate claim (exp, nbf, or iat) is a JSON number that fits in long but is outside the range supported by java.time.Instant.
The README verification example documents handling invalid tokens through JWTVerificationException:
try {
decodedJWT = verifier.verify(token);
} catch (JWTVerificationException exception) {
// Invalid signature/claims
}
For the out-of-range NumericDate case, the exception escapes as DateTimeException before signature verification reaches the usual invalid-token path.
The relevant code path in 4.5.2 / current master is:
JWTVerifier.verify(String)constructs aJWTDecoderbefore verifying the decoded token.
Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/JWTVerifier.java#L450-L452JWTParser.parsePayload(...)catchesIOExceptionfrom Jackson parsing.
Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/impl/JWTParser.java#L39-L46PayloadDeserializer.getInstantFromSeconds(...)checkscanConvertToLong(), then callsInstant.ofEpochSecond(node.asLong()).
Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/impl/PayloadDeserializer.java#L72-L81
9223372036854775807 passes the long conversion check but is outside the valid Instant epoch-second range. The result is an unchecked DateTimeException instead of a JWTVerificationException / JWTDecodeException.
Expected behavior:
Out-of-range registered NumericDate claims should be rejected through the library's normal invalid-token exception boundary.
Actual behavior:
JWTVerifier.verify(String) throws java.time.DateTimeException.
Reproduction
Create the following files in an empty directory.
First create the source directory:
mkdir -p src/main/java/repro
pom.xml:
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>repro</groupId>
<artifactId>java-jwt-numericdate-repro</artifactId>
<version>1.0.0</version>
<properties>
<maven.compiler.source>11</maven.compiler.source>
<maven.compiler.target>11</maven.compiler.target>
</properties>
<dependencies>
<dependency>
<groupId>com.auth0</groupId>
<artifactId>java-jwt</artifactId>
<version>4.5.2</version>
</dependency>
</dependencies>
<build>
<plugins>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>exec-maven-plugin</artifactId>
<version>3.5.0</version>
</plugin>
</plugins>
</build>
</project>
src/main/java/repro/NumericDateRepro.java:
package repro;
import com.auth0.jwt.JWT;
import com.auth0.jwt.algorithms.Algorithm;
import com.auth0.jwt.exceptions.JWTVerificationException;
import java.nio.charset.StandardCharsets;
import java.time.DateTimeException;
import java.util.Base64;
public final class NumericDateRepro {
public static void main(String[] args) {
String payload = "{\"exp\":9223372036854775807}";
String token = base64Url("{\"alg\":\"HS256\",\"typ\":\"JWT\"}") + "."
+ base64Url(payload) + ".invalidsig";
try {
JWT.require(Algorithm.HMAC256("secret")).build().verify(token);
System.out.println("unexpected: token accepted");
System.exit(2);
} catch (JWTVerificationException expectedBoundary) {
System.out.println("expected boundary: " + expectedBoundary.getClass().getName());
System.exit(0);
} catch (DateTimeException escaped) {
System.out.println("reproduced unchecked exception: " + escaped.getClass().getName());
System.out.println("payload=" + payload);
System.exit(1);
}
}
private static String base64Url(String value) {
return Base64.getUrlEncoder()
.withoutPadding()
.encodeToString(value.getBytes(StandardCharsets.UTF_8));
}
}
Run:
mvn -q compile exec:java -Dexec.mainClass=repro.NumericDateRepro
Observed result:
reproduced unchecked exception: java.time.DateTimeException
payload={"exp":9223372036854775807}
Success / failure oracle:
- Current behavior: the command prints
reproduced unchecked exception: java.time.DateTimeExceptionand exits with status1. - Expected fixed behavior: the command prints
expected boundary: ...JWTVerificationException...or another library-controlled invalid-token exception and exits with status0.
The same behavior can be exercised with nbf or iat instead of exp.
Additional context
No response
java-jwt version
4.5.2
Java version
Java 11
- Lingua principale
- Java
- Stelle
- 6.2k
- Fork
- 947
- Merge medio
- 52m
- PR unite (30g)
- 3
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di auth0/java-jwt
-
Date claims before the Unix epoch are rounded toward zeroForse già presa @hossam1244 l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 4/5 3-5 giorni Idoneità per principianti 42/100
I maintainer di solito rispondono entro 1 giorno
-
Upgrade Jackson 2 => Jackson 3Forse già presa Una pull request collegata a questa issue è aperta o già unita. Apertafeature request
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
auth0/java-jwt#730 · 6 commenti · 16 reazioni ·
I maintainer di solito rispondono entro 1 giorno
-
Read the payload written by withPayloadForse già presa Una pull request collegata a questa issue è aperta o già unita. Apertafeature request
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
auth0/java-jwt#725 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
feature request
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di auth0/java-jwt
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
apache/skywalking#14120 ·
I maintainer di solito rispondono entro 1 giorno
-
[Feature] 关于启动游戏进度条显示的优化Apertaenhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
HMCL-dev/HMCL#6943 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
micronaut-projects/micronaut-core#13677 ·
I maintainer di solito rispondono entro 1 giorno
-
new feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
apache/rocketmq-dashboard#5594 ·
I maintainer di solito rispondono entro 3 giorni