This is an automated email from the ASF dual-hosted git repository. smolnar82 pushed a commit to branch knox_idf in repository https://gitbox.apache.org/repos/asf/knox.git
commit c74d837e0f56d1b0840ac37fa0861bc59c4da828 Author: Sandor Molnar <[email protected]> AuthorDate: Tue Aug 11 23:38:37 2026 +0200 KNOX-3414: advertise only S256 in discovery code_challenge_methods_supported (review finding M8) The discovery document listed ["plain","S256"] for code_challenge_methods_supported, but AuthorizeResource rejects every code_challenge_method other than S256. A client that trusted discovery and used plain PKCE was then rejected at /authorize. Drop "plain" so discovery matches enforcement. Covered by DiscoveryResourcePkceMethodsTest. Co-Authored-By: Claude Opus 4.8 <[email protected]> --- .../gateway/service/knoxidf/DiscoveryResource.java | 4 +- .../knoxidf/DiscoveryResourcePkceMethodsTest.java | 52 ++++++++++++++++++++++ 2 files changed, 55 insertions(+), 1 deletion(-) diff --git a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java index eb6584f3e..e55ea817d 100644 --- a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java +++ b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResource.java @@ -71,7 +71,9 @@ public class DiscoveryResource { config.put("grant_types_supported", new String[]{KnoxIDFConstants.AUTH_CODE, KnoxIDFConstants.REFRESH_TOKEN}); config.put("scopes_supported", KnoxIDFConstants.DEFAULT_SCOPES); config.put("id_token_signing_alg_values_supported", new String[]{"RS256"}); - config.put("code_challenge_methods_supported", new String[]{KnoxIDFConstants.PKCE_METHOD_PLAIN, KnoxIDFConstants.PKCE_METHOD_S256}); + // Advertise only S256: AuthorizeResource rejects any other code_challenge_method (including + // "plain"), so discovery must not claim "plain" support it does not honor. + config.put("code_challenge_methods_supported", new String[]{KnoxIDFConstants.PKCE_METHOD_S256}); return Response.ok(JsonUtils.renderAsJsonString(config)).build(); } diff --git a/gateway-service-knoxidf/src/test/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResourcePkceMethodsTest.java b/gateway-service-knoxidf/src/test/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResourcePkceMethodsTest.java new file mode 100644 index 000000000..dfb1438cf --- /dev/null +++ b/gateway-service-knoxidf/src/test/java/org/apache/knox/gateway/service/knoxidf/DiscoveryResourcePkceMethodsTest.java @@ -0,0 +1,52 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. See the NOTICE file distributed with this + * work for additional information regarding copyright ownership. The ASF + * licenses this file to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * <p> + * http://www.apache.org/licenses/LICENSE-2.0 + * <p> + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT + * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the + * License for the specific language governing permissions and limitations under + * the License. + */ +package org.apache.knox.gateway.service.knoxidf; + +import static org.junit.Assert.assertFalse; +import static org.junit.Assert.assertTrue; + +import java.net.URI; + +import javax.ws.rs.core.Response; +import javax.ws.rs.core.UriInfo; + +import org.easymock.EasyMock; +import org.junit.Test; + +/** + * Verifies discovery advertises only the PKCE methods it actually honors (review finding M8). + * AuthorizeResource rejects any code_challenge_method other than S256, so the discovery document + * must not list "plain" -- a client that trusts discovery and sends plain would be rejected at + * /authorize. + */ +public class DiscoveryResourcePkceMethodsTest { + + @Test + public void testCodeChallengeMethodsAdvertisesOnlyS256() { + final UriInfo uriInfo = EasyMock.createNiceMock(UriInfo.class); + EasyMock.expect(uriInfo.getBaseUri()).andReturn(URI.create("https://knox:8443/gateway/knoxidf/")).anyTimes(); + EasyMock.replay(uriInfo); + + final Response response = new DiscoveryResource().getConfig(uriInfo); + final String body = String.valueOf(response.getEntity()); + + assertTrue("Discovery must advertise S256 PKCE support.", + body.contains("code_challenge_methods_supported") && body.contains("S256")); + assertFalse("Discovery must not advertise 'plain' PKCE, which /authorize rejects.", + body.contains("plain")); + } +}
