RequestValidator.validate incorrectly decodes query string when removing port
@bhaskar16 is already working on this.
Since Nov 18, 2024.
Assessment
This issue has not been assessed yet.
Description
Issue Summary
When removing the port RequestValidator.validate incorrectly decodes the path, query, and fragment.
e.g.
https://someurl.com:443/somepath?param1=client%3AAnonymous
is converted to
https://someurl.com/somepath?param1=client:Anonymous
A suggestion is to consider using getRawPath, getRawQuery, and getRawFragment instead.
Steps to Reproduce
- The snippet below demonstrates the issue. The
validateoutput should be the same for both URLs.
Code Snippet
import java.net.URI;
import java.util.HashMap;
import com.twilio.security.RequestValidator;
...
String url1 = "https://someurl.com/somepath?param1=client%3AAnonymous";
String url2 = "https://someurl.com:443/somepath?param1=client%3AAnonymous";
String signature = "PM+bjB+ITJ9a3LIYStKWOTMZMlU=";
RequestValidator r= new RequestValidator("1234567890");
System.out.println("valid without port?: " + r.validate(url1, new HashMap<>(), signature));
System.out.println("valid with port?: " + r.validate(url2, new HashMap<>(), signature));
Exception/Log
valid without port?: true
valid with port?: false
Technical details:
- twilio-java version: 7.55.3 (latest as of submission)
- java version: 1.8.0_161
- Dominant language
- Java
- Stars
- 529
- Forks
- 453
- Avg merge
- 1h 14m
- Merged PRs (30d)
- 1
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from twilio/twilio-java
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
twilio/twilio-java#976 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
twilio/twilio-java#975 ·
-
[BUG] Sip.Builder(String) drops SIP destinations with an explicit port when the scheme is omittedOpentype: bug
Difficulty 3/5 1-2 days Newbie friendliness 55/100
twilio/twilio-java#982 ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
twilio/twilio-java#960 ·
-
MessageIntent is not supported in the Java SDKMay be free again A pull request for this issue was closed without being merged. Open
Difficulty 3/5 1-2 days Newbie friendliness 55/100
twilio/twilio-java#950 · 2 comments ·
All issues in twilio/twilio-java
Similar issues
-
`GET /v1/event/token/{uuid}` can report a BOM upload as done before policy evaluation and metrics have finishedPossibly taken @Zargath claimed this today. Opendefect in triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
DependencyTrack/dependency-track#7646 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
floci-io/floci#5425 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
objectionary/eo-graphs#80 ·
-
WebMvcStreamableServerTransportProvider: idle-session eviction stops permanently after a NullPointerException when a session is deleted mid-sweepPossibly taken @lejuho claimed this today. Openstatus: waiting-for-triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
spring-projects/spring-ai#7133 ·
Maintainers usually reply within 6 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
objectionary/jucs#141 ·
Maintainers usually reply within 1 day