fo
ForgeRock
GitHub
forgerock
Workspace
GitHub
CI Pipeline Executions
Current execution
Succeeded
SDKS-5448-composed-urls
Runs and Agents
Timeline
Beta
Configuration
Self-Healing CI
Project Graph
Circular Dependencies
Enterprise
Resource Usage
Analysis
Conformance
Enterprise
Runs
Current run
Succeeded
Tasks
Resource Usage
Insights
Compare tasks
Analytics
Sign in
Toggle sidebar
fix(token-vault): compose vault-owned AM URLs for endpoint dispatch (SDKS-5448) The three token-carrying branches (token exchange, revoke, end session) keep keyword detection but fetch vault-composed URLs from generateAmUrls instead of the attacker-supplied request URL, so tokens can never be routed to attacker-chosen destinations. Adds a userinfo branch (composed URL, Bearer header), denies other AM-origin requests with an explicit error reply, and composes id_token_hint onto the vault's endSession URL. Adds e2e edge-case coverage to token-vault-suites covering endpoint-name in query strings and percent-encoded endpoint paths. No percent-decoding required.
nx-cloud record -- nx format:check --verbose
⌘K
Succeeded
nx-cloud record -- nx format:check --verbose
Click to copy
Linux
4 CPU cores
c8c203c5
594
GitHub
forgerock
Workspace