Copilot commented on code in PR #445:
URL: https://github.com/apache/commons-codec/pull/445#discussion_r4112565555
##########
src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java:
##########
@@ -50,6 +50,10 @@ void testSha2CryptRounds() {
@Test
void testSha2CryptWrongSalt() {
assertThrows(IllegalArgumentException.class, () ->
Sha2Crypt.sha512Crypt("secret".getBytes(StandardCharsets.UTF_8), "xx"));
+ assertThrows(IllegalArgumentException.class,
+ () ->
Sha2Crypt.sha256Crypt("secret".getBytes(StandardCharsets.UTF_8),
"$5$notrounds=1000$asdfasdf"));
+ assertThrows(IllegalArgumentException.class,
+ () ->
Sha2Crypt.sha512Crypt("secret".getBytes(StandardCharsets.UTF_8),
"$6$rounds=1000$äöüäöü"));
Review Comment:
This regression case does not exercise the previously accepted
invalid-character suffix: the first salt character after `$6$rounds=1000$` is
already `ä`, so the old pattern could not match it even with its unanchored
`.*`. Put a valid prefix before the non-alphabet character (for example
`abcä...`) so the test fails before this regex change and verifies that
trailing invalid salt input is rejected.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]