Skip to content

[#726] Reject malformed bracketed IPv6 hosts in HostPort - #732

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix/issue-726-aci-ipv6-host
Jul 12, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:fix/issue-726-aci-ipv6-host

Conversation

@vharseko

Copy link
Copy Markdown
Member

Fixes #726.

Problem

Decoding an ACI with a malformed IPv6 host inside userdn crashed with a raw StringIndexOutOfBoundsException instead of the expected AciException:

(version 3.0; acl "f"; allow (search) userdn="q://[:1"; )

HostPort.removeExtraChars assumed that any host containing [ is a well-formed bracketed IPv6 literal and blindly stripped the first and last characters, so the host "[" blew up on substring(1, 0). Other malformed inputs ("[x", "ab[cd") were silently mangled instead of rejected.

Fix

  • HostPort.removeExtraChars now validates the bracket syntax: hosts without brackets pass through unchanged, [...] with non-empty content gets the brackets stripped, and anything else that starts or ends with a bracket throws IllegalArgumentException.
  • HostPort.valueOf detects a string starting with [ that is not of the form [...]:port / [...] right away (previously this check only fired when the string contained more than one colon), and rejects empty input (which also used to throw StringIndexOutOfBoundsException on charAt(0)).

LDAPURL.decode already converts IllegalArgumentException into a DirectoryException, which UserDN.decode wraps into AciException — so ACI decoding now fails cleanly, as expected in the issue, with no changes needed in the upper layers.

Tests

  • HostPortTest: 10 new cases — both crashing inputs from the issue (valueOf("[:1"), new HostPort("[", 1)), missing opening/closing brackets, empty brackets, empty string, plus a positive control for a valid bracketed IPv6 host.
  • UserDNTestCase: the ACI from the issue and an ldap://[::1:389/... variant must fail with AciException; a well-formed ldap://[::1]:389/... must still decode.

Verified that the regression test reproduces the original failure: on the unfixed code it fails with StringIndexOutOfBoundsException: Range [1, 0) out of bounds for length 1. With the fix, HostPortTest + UserDNTestCase (42/42) and LDAPURLTest + LDAPURLTestCase (37/37) are green.

…rm#726)

An ACI such as (version 3.0; acl "f"; allow (search) userdn="q://[:1"; )
crashed Aci.decode with StringIndexOutOfBoundsException: removeExtraChars
assumed any host containing '[' was a well-formed "[IPv6]" literal and
blindly stripped the first and last characters.

Validate the bracket syntax instead: throw IllegalArgumentException for
hosts that start or end with a bracket without forming "[...]", detect
"[host" without "]:" already in HostPort.valueOf, and guard valueOf
against empty input. LDAPURL.decode already converts the IAE to a
DirectoryException, so ACI decoding now fails with the expected
AciException.
@vharseko vharseko added bug ACI Access Control Instructions subsystem labels Jul 10, 2026
@vharseko
vharseko requested a review from maximthomas July 10, 2026 20:36
@vharseko vharseko added the tests Test suites: fixing, enabling, un-disabling label Jul 10, 2026
@vharseko vharseko changed the title Reject malformed bracketed IPv6 hosts in HostPort (#726) [#726] Reject malformed bracketed IPv6 hosts in HostPort Jul 10, 2026
@vharseko
vharseko merged commit 07bad95 into OpenIdentityPlatform:master Jul 12, 2026
17 checks passed
@vharseko
vharseko deleted the fix/issue-726-aci-ipv6-host branch July 12, 2026 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ACI Access Control Instructions subsystem bug tests Test suites: fixing, enabling, un-disabling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validation for incorrect IPv6 host is missing in userDN of ACI

2 participants