Skip to content

Commit

Permalink
Merge pull request #7646 from AnjanaSamindraPerera/cookie-issue
Browse files Browse the repository at this point in the history
Encode spId parameter
  • Loading branch information
AnjanaSamindraPerera authored Feb 18, 2025
2 parents ac67e72 + d4db891 commit 91ec588
Show file tree
Hide file tree
Showing 4 changed files with 10 additions and 3 deletions.
5 changes: 5 additions & 0 deletions .changeset/three-cups-repeat.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"@wso2is/identity-apps-core": patch
---

Encode spId of application
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@
<%@ page import="org.wso2.carbon.identity.mgt.endpoint.util.client.PreferenceRetrievalClient" %>
<%@ page import="org.wso2.carbon.identity.mgt.endpoint.util.client.PreferenceRetrievalClientException" %>
<%@ page import="org.wso2.carbon.identity.mgt.endpoint.util.IdentityManagementEndpointConstants" %>
<%@ page import="org.owasp.encoder.Encode" %>

<%-- Include tenant context --%>
<%@ include file="tenant-resolve.jsp"%>
Expand Down Expand Up @@ -303,7 +304,8 @@
request.getRequestDispatcher("sms-otp.jsp").forward(request, response);
return;
}
request.setAttribute("spId", request.getParameter("spId"));
String spId = Encode.forJava(request.getParameter("spId"));
request.setAttribute("spId", spId);
request.getRequestDispatcher("password-reset.jsp").forward(request, response);
} else if (RecoveryStage.RESET.equalsValue(recoveryStage)) {
request.setAttribute("useRecoveryV2API", "true");
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@
IdentityManagementEndpointUtil.getStringValue(request.getSession().getAttribute("confirmationKey"));
String newPassword = request.getParameter("reset-password");
String callback = request.getParameter("callback");
String spId = request.getParameter("spId");
String spId = Encode.forJava(request.getParameter("spId"));
if (StringUtils.isBlank(spId)) {
spId = (String)request.getAttribute("spId");
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@
String confirmLiteReg = (String) request.getAttribute("confirmLiteReg");
String resendUsername = request.getParameter("username");
String sp = Encode.forJava(request.getParameter("sp"));
String spId = request.getParameter("spId");
String spId = Encode.forJava(request.getParameter("spId"));
String sessionDataKey = (String) request.getAttribute("sessionDataKey");
String applicationAccessURLWithoutEncoding = null;
String tenantedMyaccountURL = null;
Expand Down

0 comments on commit 91ec588

Please sign in to comment.