Out-of-range NumericDate claims can throw unchecked DateTimeException during verification
Maintainer thường phản hồi trong vòng 1 ngày
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- java
- Lĩnh vực
- authentication, security
Hướng nghiên cứu
Bắt đầu từ JWTVerifier.verify(String), sau đó đọc JWTParser.parsePayload(...) và PayloadDeserializer.getInstantFromSeconds(...) trong các tệp được tham chiếu tại lib/src/main/java/com/auth0/jwt. Chạy bản tái hiện Maven được cung cấp với giá trị exp nằm ngoài phạm vi và xác minh rằng exp, nbf và iat không còn thoát ra dưới dạng DateTimeException, mà đi đến ranh giới ngoại lệ của thư viện dành cho token không hợp lệ.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Checklist
- I have looked into the Readme and Examples, and have not found a suitable solution or answer.
- I have looked into the API documentation and have not found a suitable solution or answer.
- I have searched the issues and have not found a suitable solution or answer.
- I have searched the Auth0 Community forums and have not found a suitable solution or answer.
- I agree to the terms within the Auth0 Code of Conduct.
Description
JWTVerifier.verify(String) can throw java.time.DateTimeException when a registered NumericDate claim (exp, nbf, or iat) is a JSON number that fits in long but is outside the range supported by java.time.Instant.
The README verification example documents handling invalid tokens through JWTVerificationException:
try {
decodedJWT = verifier.verify(token);
} catch (JWTVerificationException exception) {
// Invalid signature/claims
}
For the out-of-range NumericDate case, the exception escapes as DateTimeException before signature verification reaches the usual invalid-token path.
The relevant code path in 4.5.2 / current master is:
JWTVerifier.verify(String)constructs aJWTDecoderbefore verifying the decoded token.
Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/JWTVerifier.java#L450-L452JWTParser.parsePayload(...)catchesIOExceptionfrom Jackson parsing.
Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/impl/JWTParser.java#L39-L46PayloadDeserializer.getInstantFromSeconds(...)checkscanConvertToLong(), then callsInstant.ofEpochSecond(node.asLong()).
Reference: https://github.com/auth0/java-jwt/blob/695fd2bea64b8466b872a9d0c2e7019fee7ac86f/lib/src/main/java/com/auth0/jwt/impl/PayloadDeserializer.java#L72-L81
9223372036854775807 passes the long conversion check but is outside the valid Instant epoch-second range. The result is an unchecked DateTimeException instead of a JWTVerificationException / JWTDecodeException.
Expected behavior:
Out-of-range registered NumericDate claims should be rejected through the library's normal invalid-token exception boundary.
Actual behavior:
JWTVerifier.verify(String) throws java.time.DateTimeException.
Reproduction
Create the following files in an empty directory.
First create the source directory:
mkdir -p src/main/java/repro
pom.xml:
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>repro</groupId>
<artifactId>java-jwt-numericdate-repro</artifactId>
<version>1.0.0</version>
<properties>
<maven.compiler.source>11</maven.compiler.source>
<maven.compiler.target>11</maven.compiler.target>
</properties>
<dependencies>
<dependency>
<groupId>com.auth0</groupId>
<artifactId>java-jwt</artifactId>
<version>4.5.2</version>
</dependency>
</dependencies>
<build>
<plugins>
<plugin>
<groupId>org.codehaus.mojo</groupId>
<artifactId>exec-maven-plugin</artifactId>
<version>3.5.0</version>
</plugin>
</plugins>
</build>
</project>
src/main/java/repro/NumericDateRepro.java:
package repro;
import com.auth0.jwt.JWT;
import com.auth0.jwt.algorithms.Algorithm;
import com.auth0.jwt.exceptions.JWTVerificationException;
import java.nio.charset.StandardCharsets;
import java.time.DateTimeException;
import java.util.Base64;
public final class NumericDateRepro {
public static void main(String[] args) {
String payload = "{\"exp\":9223372036854775807}";
String token = base64Url("{\"alg\":\"HS256\",\"typ\":\"JWT\"}") + "."
+ base64Url(payload) + ".invalidsig";
try {
JWT.require(Algorithm.HMAC256("secret")).build().verify(token);
System.out.println("unexpected: token accepted");
System.exit(2);
} catch (JWTVerificationException expectedBoundary) {
System.out.println("expected boundary: " + expectedBoundary.getClass().getName());
System.exit(0);
} catch (DateTimeException escaped) {
System.out.println("reproduced unchecked exception: " + escaped.getClass().getName());
System.out.println("payload=" + payload);
System.exit(1);
}
}
private static String base64Url(String value) {
return Base64.getUrlEncoder()
.withoutPadding()
.encodeToString(value.getBytes(StandardCharsets.UTF_8));
}
}
Run:
mvn -q compile exec:java -Dexec.mainClass=repro.NumericDateRepro
Observed result:
reproduced unchecked exception: java.time.DateTimeException
payload={"exp":9223372036854775807}
Success / failure oracle:
- Current behavior: the command prints
reproduced unchecked exception: java.time.DateTimeExceptionand exits with status1. - Expected fixed behavior: the command prints
expected boundary: ...JWTVerificationException...or another library-controlled invalid-token exception and exits with status0.
The same behavior can be exercised with nbf or iat instead of exp.
Additional context
No response
java-jwt version
4.5.2
Java version
Java 11
- Ngôn ngữ chính
- Java
- Star
- 6.2k
- Fork
- 947
- Merge trung bình
- 52 phút
- Pull request đã merge (30 ngày)
- 3
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của auth0/java-jwt
-
Date claims before the Unix epoch are rounded toward zeroCó thể đã có người làm @hossam1244 đã nhận 5 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 42/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Upgrade Jackson 2 => Jackson 3Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởfeature request
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
auth0/java-jwt#730 · 6 bình luận · 17 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Read the payload written by withPayloadCó thể đã có người làm @marktech0813 đã nhận 332 ngày trước. Đang mởfeature request
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
auth0/java-jwt#725 · 4 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature request
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của auth0/java-jwt
Issue tương tự
-
[i18n] 安装实例完成后的成功提示未正确本地化Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
PCL-Community/PCL-CE#3658 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Team/Identity Server Core Type/Improvement U2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
wso2/product-is#28553 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Feature]: Page CreationĐang mởfrontend
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
Paul-Austin-Oswego-CSC480-HCI521/gift-app#116 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
dependencies java
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 62/100
micrometer-metrics/tracing#1588 ·
Maintainer thường phản hồi trong vòng 1 ngày