Skip to content

Fix JwtClaimValidator null claim handling - #19348

Open
xfocus3 wants to merge 2 commits into
spring-projects:mainfrom
xfocus3:gh-19346-jwt-claim-null
Open

xfocus3 wants to merge 2 commits into
spring-projects:mainfrom
xfocus3:gh-19346-jwt-claim-null

Conversation

@xfocus3

@xfocus3 xfocus3 commented Jun 18, 2026

Copy link
Copy Markdown

Summary

  • Restore JwtClaimValidator behavior so custom claim predicates receive null for missing or null-valued claims.
  • Add regression coverage for a missing loa claim where the configured predicate accepts null.

Fixes gh-19346

Testing

  • ./gradlew :spring-security-oauth2-jose:test --tests org.springframework.security.oauth2.jwt.JwtClaimValidatorTests.validateWhenClaimIsMissingAndTestAcceptsNullThenReturnsSuccess --no-daemon
  • ./gradlew :spring-security-oauth2-jose:test --tests org.springframework.security.oauth2.jwt.JwtClaimValidatorTests --no-daemon
  • ./gradlew :spring-security-oauth2-jose:test --no-daemon
  • git diff --check

Signed-off-by: Ahmed El amraouiyine <amraouiyine@gmail.com>
Cover explicit null claims and null-rejecting predicates.

Refs spring-projectsgh-19346

Signed-off-by: Ahmed El amraouiyine <xfocus29@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

with spring-security-oatuh2-jose-7.1.0 a jwt with loa value null always returns an error

2 participants