Describe the bug
Spring Authorization Server accepts malformed S256 code_challenge values at the authorization endpoint. With an authenticated user, a challenge that is too short or contains an invalid character results in an authorization code. With an anonymous user, a too-short challenge proceeds to the login redirect. This is not a a PKCE bypass.
To Reproduce
Clone the sample below and run mvn test. It uses Spring Boot 4.1.1, which manages Spring Security 7.1.1, and the default authorization server configuration. The suite has one passing valid-challenge control and three failing malformed-challenge assertions.
Expected behavior
Reject a malformed code_challenge as invalid_request during authorization request validation, regardless of whether the user is authenticated. Rejection should happen before either issuing a code or redirecting to login.
RFC 7636 §4.2 defines the challenge’s length and allowed characters. RFC 6749 §4.1.1 places request validation before user authentication, and §4.1.2.1 defines invalid_request for an invalid parameter value. The Spring Security 7.1.1 challenge validator checks presence and method, but not challenge length or characters.
Sample
Spring-Auth-Server-PKCE-Challenge-Validation-Repro
I’m happy to contribute a fix and tests if desired.
Acknowledgement: AI coding assistance was used in preparing this report.
Describe the bug
Spring Authorization Server accepts malformed S256 code_challenge values at the authorization endpoint. With an authenticated user, a challenge that is too short or contains an invalid character results in an authorization code. With an anonymous user, a too-short challenge proceeds to the login redirect. This is not a a PKCE bypass.
To Reproduce
Clone the sample below and run mvn test. It uses Spring Boot 4.1.1, which manages Spring Security 7.1.1, and the default authorization server configuration. The suite has one passing valid-challenge control and three failing malformed-challenge assertions.
Expected behavior
Reject a malformed
code_challengeasinvalid_requestduring authorization request validation, regardless of whether the user is authenticated. Rejection should happen before either issuing a code or redirecting to login.RFC 7636 §4.2 defines the challenge’s length and allowed characters. RFC 6749 §4.1.1 places request validation before user authentication, and §4.1.2.1 defines
invalid_requestfor an invalid parameter value. The Spring Security 7.1.1 challenge validator checks presence and method, but not challenge length or characters.Sample
Spring-Auth-Server-PKCE-Challenge-Validation-Repro
I’m happy to contribute a fix and tests if desired.
Acknowledgement: AI coding assistance was used in preparing this report.