From 28e69c377ffb10fa5a013dec070d321669dc18d8 Mon Sep 17 00:00:00 2001 From: Harry Smith Date: Mon, 17 Feb 2020 08:36:39 +0000 Subject: [PATCH] DWN-31929 : mitigate open id common XSS vulnerability --- openid-connect-common/pom.xml | 44 +++++++++++++++ .../connect/web/UserInfoInterceptor.java | 55 ++++++++++++++++++- .../web/UserInfoInterceptorSpec.groovy | 41 ++++++++++++++ pom.xml | 23 ++++++++ 4 files changed, 160 insertions(+), 3 deletions(-) create mode 100644 openid-connect-common/src/test/groovy/org/mitre/openid/connect/web/UserInfoInterceptorSpec.groovy diff --git a/openid-connect-common/pom.xml b/openid-connect-common/pom.xml index bc910d1cd..79123a854 100644 --- a/openid-connect-common/pom.xml +++ b/openid-connect-common/pom.xml @@ -87,6 +87,19 @@ org.bouncycastle bcprov-jdk15on + + org.jsoup + jsoup + + + + org.codehaus.groovy + groovy-all + + + org.spockframework + spock-core + jar @@ -101,6 +114,37 @@ ${java-version} + + org.codehaus.gmavenplus + gmavenplus-plugin + 1.7.0 + + + + addTestStubSources + compileTests + removeTestStubs + + + + + ${project.build.directory}/generated-groovy-stubs + ${project.build.directory}/generated-groovy-test-stubs + + + + org.apache.maven.plugins + maven-surefire-plugin + 2.18.1 + + + ${project.build.testOutputDirectory} + + **/*Test.java + **/*Spec.java + + + org.mitre @@ -607,6 +625,11 @@ wro4j-extensions 1.8.0 + + org.jsoup + jsoup + 1.10.3 +