fix(auth): handle saml logout and xml encryption padding

This commit is contained in:
mac
2026-07-17 09:42:12 +08:00
parent 157f0c65cb
commit b151356045
7 changed files with 112 additions and 12 deletions
+2 -7
View File
@@ -246,7 +246,7 @@ func decryptAESCBC(value, key []byte) ([]byte, error) {
cipherText := value[block.BlockSize():]
plain := make([]byte, len(cipherText))
cipher.NewCBCDecrypter(block, iv).CryptBlocks(plain, cipherText)
plain, err = pkcs7Unpad(plain, block.BlockSize())
plain, err = xmlEncCBCUnpad(plain, block.BlockSize())
if err != nil {
return nil, err
}
@@ -274,7 +274,7 @@ func decryptAESGCM(value, key []byte) ([]byte, error) {
return plain, nil
}
func pkcs7Unpad(value []byte, blockSize int) ([]byte, error) {
func xmlEncCBCUnpad(value []byte, blockSize int) ([]byte, error) {
if len(value) == 0 || len(value)%blockSize != 0 {
return nil, errors.New("invalid saml assertion padding length")
}
@@ -282,11 +282,6 @@ func pkcs7Unpad(value []byte, blockSize int) ([]byte, error) {
if padding == 0 || padding > blockSize || padding > len(value) {
return nil, errors.New("invalid saml assertion padding")
}
for _, b := range value[len(value)-padding:] {
if int(b) != padding {
return nil, errors.New("invalid saml assertion padding bytes")
}
}
return value[:len(value)-padding], nil
}