Skip to content

Delete legacy assertion parser#52

Merged
njwatson32 merged 1 commit into
masterfrom
delete-bad-parser
May 19, 2026
Merged

Delete legacy assertion parser#52
njwatson32 merged 1 commit into
masterfrom
delete-bad-parser

Conversation

@njwatson32

Copy link
Copy Markdown
Collaborator

No description provided.

… is incomplete and does not check path and query. (2) Parser takes both assertion and audience from HttpServletRequest allowing an attacker to modify Host header to match stolen assertion
@njwatson32 njwatson32 merged commit 48f3ab9 into master May 19, 2026
2 checks passed
@njwatson32 njwatson32 deleted the delete-bad-parser branch May 19, 2026 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants