Fix urlsafe MessageVerifier not to include padding

urlsafe option was introduced to MessageVerifier in
09c3f36a96 but it can generate strings
containing padding character ("=") which is not urlsafe.

Fix not to pad when base64 encode.
This commit is contained in:
Shouichi Kamiya 2022-06-22 15:15:02 +09:00
parent 6d8df0af70
commit 08afa160a5
2 changed files with 6 additions and 1 deletions

View File

@ -210,7 +210,7 @@ module ActiveSupport
private
def encode(data)
@urlsafe ? Base64.urlsafe_encode64(data) : Base64.strict_encode64(data)
@urlsafe ? Base64.urlsafe_encode64(data, padding: false) : Base64.strict_encode64(data)
end
def decode(data)

View File

@ -360,6 +360,11 @@ class MessageVerifierUrlsafeTest < MessageVerifierMetadataTest
assert_equal message, URI.encode_www_form_component(message)
end
def test_no_padding
message = generate("a")
assert_not_includes message, "="
end
private
def verifier_options
{ urlsafe: true }