Browse Source

SEC-1772: remote URL decoding of targetUrlParameter in AbstractAuthenticationTargetUrlRequestHandler.

pull/1/head
Luke Taylor 15 years ago
parent
commit
700fa9e0b6
  1. 6
      web/src/main/java/org/springframework/security/web/authentication/AbstractAuthenticationTargetUrlRequestHandler.java

6
web/src/main/java/org/springframework/security/web/authentication/AbstractAuthenticationTargetUrlRequestHandler.java

@ -91,12 +91,6 @@ public abstract class AbstractAuthenticationTargetUrlRequestHandler { @@ -91,12 +91,6 @@ public abstract class AbstractAuthenticationTargetUrlRequestHandler {
targetUrl = request.getParameter(targetUrlParameter);
if (StringUtils.hasText(targetUrl)) {
try {
targetUrl = URLDecoder.decode(targetUrl, "UTF-8");
} catch (UnsupportedEncodingException e) {
throw new IllegalStateException("UTF-8 not supported. Shouldn't be possible");
}
logger.debug("Found targetUrlParameter in request: " + targetUrl);
return targetUrl;

Loading…
Cancel
Save