Uploaded image for project: 'Apache Oltu'
  1. Apache Oltu
  2. OLTU-182

Colons in client secrets are not supported

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • oauth2-1.0.0
    • oauth2-1.0.2
    • oauth2-common
    • None

    Description

      Let me know if I'm misunderstanding, but it seems like the basic auth spec allows colons in the password: https://tools.ietf.org/html/rfc2617#section-2

      OAuthUtils.decodeClientAuthentication just splits on a colon, thus failing if colons are used in the password.

      Attachments

        Activity

          People

            jasha Jasha Joachimsthal
            adam.t.campbell Adam Campbell
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: