This is an automated email from the ASF dual-hosted git repository.

smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git

commit c74d837e0f56d1b0840ac37fa0861bc59c4da828
Author: Sandor Molnar <[email protected]>
AuthorDate: Tue Aug 11 23:38:37 2026 +0200

    KNOX-3414: advertise only S256 in discovery 
code_challenge_methods_supported (review finding M8)
    
    The discovery document listed ["plain","S256"] for
    code_challenge_methods_supported, but AuthorizeResource rejects every
    code_challenge_method other than S256. A client that trusted discovery and 
used
    plain PKCE was then rejected at /authorize.
    
    Drop "plain" so discovery matches enforcement.
    
    Covered by DiscoveryResourcePkceMethodsTest.
    
    Co-Authored-By: Claude Opus 4.8 <[email protected]>
---
 .../gateway/service/knoxidf/DiscoveryResource.java |  4 +-
 .../knoxidf/DiscoveryResourcePkceMethodsTest.java  | 52 ++++++++++++++++++++++
 2 files changed, 55 insertions(+), 1 deletion(-)

diff --git 
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java
 
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java
index eb6584f3e..e55ea817d 100644
--- 
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java
+++ 
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java
@@ -71,7 +71,9 @@ public class DiscoveryResource {
         config.put("grant_types_supported", new 
String[]{KnoxIDFConstants.AUTH_CODE, KnoxIDFConstants.REFRESH_TOKEN});
         config.put("scopes_supported", KnoxIDFConstants.DEFAULT_SCOPES);
         config.put("id_token_signing_alg_values_supported", new 
String[]{"RS256"});
-        config.put("code_challenge_methods_supported", new 
String[]{KnoxIDFConstants.PKCE_METHOD_PLAIN, 
KnoxIDFConstants.PKCE_METHOD_S256});
+        // Advertise only S256: AuthorizeResource rejects any other 
code_challenge_method (including
+        // "plain"), so discovery must not claim "plain" support it does not 
honor.
+        config.put("code_challenge_methods_supported", new 
String[]{KnoxIDFConstants.PKCE_METHOD_S256});
         return Response.ok(JsonUtils.renderAsJsonString(config)).build();
     }
 
diff --git 
a/gateway-service-knoxidf/src/test/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResourcePkceMethodsTest.java
 
b/gateway-service-knoxidf/src/test/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResourcePkceMethodsTest.java
new file mode 100644
index 000000000..dfb1438cf
--- /dev/null
+++ 
b/gateway-service-knoxidf/src/test/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResourcePkceMethodsTest.java
@@ -0,0 +1,52 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with this
+ * work for additional information regarding copyright ownership. The ASF
+ * licenses this file to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ * <p>
+ * http://www.apache.org/licenses/LICENSE-2.0
+ * <p>
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
+ * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
+ * License for the specific language governing permissions and limitations 
under
+ * the License.
+ */
+package org.apache.knox.gateway.service.knoxidf;
+
+import static org.junit.Assert.assertFalse;
+import static org.junit.Assert.assertTrue;
+
+import java.net.URI;
+
+import javax.ws.rs.core.Response;
+import javax.ws.rs.core.UriInfo;
+
+import org.easymock.EasyMock;
+import org.junit.Test;
+
+/**
+ * Verifies discovery advertises only the PKCE methods it actually honors 
(review finding M8).
+ * AuthorizeResource rejects any code_challenge_method other than S256, so the 
discovery document
+ * must not list "plain" -- a client that trusts discovery and sends plain 
would be rejected at
+ * /authorize.
+ */
+public class DiscoveryResourcePkceMethodsTest {
+
+  @Test
+  public void testCodeChallengeMethodsAdvertisesOnlyS256() {
+    final UriInfo uriInfo = EasyMock.createNiceMock(UriInfo.class);
+    
EasyMock.expect(uriInfo.getBaseUri()).andReturn(URI.create("https://knox:8443/gateway/knoxidf/";)).anyTimes();
+    EasyMock.replay(uriInfo);
+
+    final Response response = new DiscoveryResource().getConfig(uriInfo);
+    final String body = String.valueOf(response.getEntity());
+
+    assertTrue("Discovery must advertise S256 PKCE support.",
+        body.contains("code_challenge_methods_supported") && 
body.contains("S256"));
+    assertFalse("Discovery must not advertise 'plain' PKCE, which /authorize 
rejects.",
+        body.contains("plain"));
+  }
+}

Reply via email to