-
Bug
-
Resolution: Done
-
Undefined
-
None
Before reporting an issue
[x] I have read and understood the above terms for submitting issues, and I understand that my issue may be closed without action if I do not follow them.
Area
No response
Describe the bug
As part of the JAX-RS features each path element allows RFC-compliant matrix parameters, although Keycloak is not using them anywhere. They are basically ignored.
It would be good to not allow any matrix parameter to harden Keycloak until we actually make use of them.
Version
main
Regression
[ ] The issue is a regression
Expected behavior
Return a 400 response when there is a semicolon in the URL
Actual behavior
Matrix parameters are silently ignored.
How to Reproduce?
Use a semicolon in a URL
Anything else?
I'll prepare a PR
- links to