1
0
mirror of synced 2026-09-12 20:25:06 +00:00

Fix TokenType Comparison Logic

Compare OAuth2AccessToken.TokenType using equals() instead of == in
BearerTokenAuthentication, since TokenType instances are not
guaranteed to be singletons and reference comparison can incorrectly
reject an otherwise-equal bearer token.

Closes gh-19377

Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com>
This commit is contained in:
Tran Ngoc Nhan
2026-06-25 15:42:42 +07:00
committed by Josh Cummings
parent 27a76a67ae
commit 02cc2e9d14
2 changed files with 31 additions and 2 deletions
@@ -53,7 +53,7 @@ public class BearerTokenAuthentication extends AbstractOAuth2TokenAuthentication
public BearerTokenAuthentication(OAuth2AuthenticatedPrincipal principal, OAuth2AccessToken credentials,
Collection<? extends GrantedAuthority> authorities) {
super(credentials, principal, credentials, authorities);
Assert.isTrue(credentials.getTokenType() == OAuth2AccessToken.TokenType.BEARER,
Assert.isTrue(OAuth2AccessToken.TokenType.BEARER.equals(credentials.getTokenType()),
"credentials must be a bearer token");
this.attributes = Collections.unmodifiableMap(new LinkedHashMap<>(principal.getAttributes()));
setAuthenticated(true);
@@ -121,7 +121,8 @@ public class BearerTokenAuthentication extends AbstractOAuth2TokenAuthentication
*/
@Override
public B token(OAuth2AccessToken token) {
Assert.isTrue(token.getTokenType() == OAuth2AccessToken.TokenType.BEARER, "token must be a bearer token");
Assert.isTrue(OAuth2AccessToken.TokenType.BEARER.equals(token.getTokenType()),
"token must be a bearer token");
super.credentials(token);
return super.token(token);
}
@@ -173,4 +173,32 @@ public class BearerTokenAuthenticationTests {
assertThat(authorities).containsExactlyInAnyOrder("FACTOR_ONE", "FACTOR_TWO");
}
// gh-19377
@Test
public void compareCredentialsHasBearerTokenType() {
Instant current = Instant.now();
Instant after1hour = Instant.now().plusSeconds(3600);
OAuth2AccessToken oAuth2AccessToken = new OAuth2AccessToken(new OAuth2AccessToken.TokenType("Bearer"), "token",
current, after1hour);
BearerTokenAuthentication authenticated = new BearerTokenAuthentication(this.principal, oAuth2AccessToken,
this.authorities);
assertThat(authenticated.getName()).isEqualTo(this.name);
assertThat(authenticated.getCredentials())
.isEqualTo(new OAuth2AccessToken(OAuth2AccessToken.TokenType.BEARER, "token", current, after1hour));
}
// gh-19377
@Test
public void toBuilderCompareCredentialsHasBearerTokenType() {
Instant current = Instant.now();
Instant after1hour = Instant.now().plusSeconds(3600);
OAuth2AccessToken oAuth2AccessToken = new OAuth2AccessToken(new OAuth2AccessToken.TokenType("Bearer"), "token",
current, after1hour);
BearerTokenAuthentication token = new BearerTokenAuthentication(this.principal, this.token, this.authorities);
BearerTokenAuthentication authenticated = token.toBuilder().token(oAuth2AccessToken).build();
assertThat(authenticated.getName()).isEqualTo(this.name);
assertThat(authenticated.getCredentials())
.isEqualTo(new OAuth2AccessToken(OAuth2AccessToken.TokenType.BEARER, "token", current, after1hour));
}
}