Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions src/test/java/com/google/crypto/tink/jwt/JwkSetConverterTest.java
Original file line number Diff line number Diff line change
Expand Up @@ -900,6 +900,38 @@ public void ecdsaWithUnknownField_toPublicKeysetHandleSuccess() throws Exception
Object unused = JwkSetConverter.toPublicKeysetHandle(jwksString);
}

@Test
public void withoutKeysField_toPublicKeysetHandleFailsWithGeneralSecurityException()
throws Exception {
// Well-formed JSON, but missing the top-level "keys" array entirely. Before the fix, this
// threw an uncaught NullPointerException instead of the documented GeneralSecurityException,
// since jsonKeyset.get("keys") returns null for a Gson JsonObject that has no such member.
String jwksString = "{}";
assertThrows(
GeneralSecurityException.class, () -> JwkSetConverter.toPublicKeysetHandle(jwksString));
}

@Test
public void keysFieldIsNotAnArray_toPublicKeysetHandleFailsWithGeneralSecurityException()
throws Exception {
// Before the fix, this threw an uncaught IllegalStateException (from
// JsonElement.getAsJsonArray()) instead of the documented GeneralSecurityException, because
// the "keys" value is read and converted outside of the method's only try/catch block.
String jwksString = "{\"keys\":\"not an array\"}";
assertThrows(
GeneralSecurityException.class, () -> JwkSetConverter.toPublicKeysetHandle(jwksString));
}

@Test
public void keysArrayContainsNonObjectElement_toPublicKeysetHandleFailsWithGeneralSecurityException()
throws Exception {
// Before the fix, this threw an uncaught IllegalStateException (from
// JsonElement.getAsJsonObject()) instead of the documented GeneralSecurityException.
String jwksString = "{\"keys\":[\"not an object\"]}";
assertThrows(
GeneralSecurityException.class, () -> JwkSetConverter.toPublicKeysetHandle(jwksString));
}

@Test
public void ecdsaWithoutAlg_toPublicKeysetHandleFails() throws Exception {
String jwksString =
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -140,6 +140,41 @@ public void testExportTinkVariantThrows() throws Exception {
GeneralSecurityException.class, () -> SignatureJwkSetConverter.fromPublicKeysetHandle(publicHandle));
}

@Test
public void withoutKeysField_toPublicKeysetHandleFailsWithGeneralSecurityException()
throws Exception {
// Well-formed JSON, but missing the top-level "keys" array entirely. Before the fix, this
// threw an uncaught NullPointerException instead of the documented GeneralSecurityException,
// since jsonKeyset.get("keys") returns null for a Gson JsonObject that has no such member.
String jwksString = "{}";
assertThrows(
GeneralSecurityException.class,
() -> SignatureJwkSetConverter.toPublicKeysetHandle(jwksString));
}

@Test
public void keysFieldIsNotAnArray_toPublicKeysetHandleFailsWithGeneralSecurityException()
throws Exception {
// Before the fix, this threw an uncaught IllegalStateException (from
// JsonElement.getAsJsonArray()) instead of the documented GeneralSecurityException, because
// the "keys" value is read and converted outside of the method's only try/catch block.
String jwksString = "{\"keys\":\"not an array\"}";
assertThrows(
GeneralSecurityException.class,
() -> SignatureJwkSetConverter.toPublicKeysetHandle(jwksString));
}

@Test
public void keysArrayContainsNonObjectElement_toPublicKeysetHandleFailsWithGeneralSecurityException()
throws Exception {
// Before the fix, this threw an uncaught IllegalStateException (from
// JsonElement.getAsJsonObject()) instead of the documented GeneralSecurityException.
String jwksString = "{\"keys\":[\"not an object\"]}";
assertThrows(
GeneralSecurityException.class,
() -> SignatureJwkSetConverter.toPublicKeysetHandle(jwksString));
}

@Test
public void testExportEcdsaDerEncodingThrows() throws Exception {
// PredefinedSignatureParameters.ECDSA_P256 is TINK variant, but even if we make it RAW,
Expand Down