Skip to content

Commit 9a961f4

Browse files
yassinraislcobucci
authored andcommitted
Fix usage of non JSON numeric values for time fractions
The RFC-7519 states that the `NumericDate` type is: > JSON numeric value representing the number of seconds from > 1970-01-01T00:00:00Z UTC until the specified UTC date/time, ignoring > leap seconds. Then also mentions that time fractions (as covered by RFC-3339) are supported: > Seconds Since the Epoch", in which each day is accounted for by > exactly 86400 seconds, other than that non-integer values can be > represented. While adding support for time fractions we've interpreted the "non-integer" really as any "non-integer" value, and used strings to guard against precision issues. That causes issues, since a string isn't a "JSON numeric value" according to the JSON specs. We observed that the 6-digit precision is not lost when doing JSON encode/decode operations, this applies that technique to make sure we comply to the specs and have "rounding issues" when dealing with floats.
1 parent ad4729f commit 9a961f4

File tree

5 files changed

+16
-13
lines changed

5 files changed

+16
-13
lines changed

src/Encoding/MicrosecondBasedDateConversion.php

Lines changed: 4 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -25,16 +25,13 @@ public function formatClaims(array $claims): array
2525
return $claims;
2626
}
2727

28-
/** @return int|string */
28+
/** @return int|float */
2929
private function convertDate(DateTimeImmutable $date)
3030
{
31-
$seconds = $date->format('U');
32-
$microseconds = $date->format('u');
33-
34-
if ((int) $microseconds === 0) {
35-
return (int) $seconds;
31+
if ($date->format('u') === '000000') {
32+
return (int) $date->format('U');
3633
}
3734

38-
return $seconds . '.' . $microseconds;
35+
return (float) $date->format('U.u');
3936
}
4037
}

src/Token/Parser.php

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,12 @@
1212
use function count;
1313
use function explode;
1414
use function is_array;
15+
use function is_string;
16+
use function json_encode;
1517
use function strpos;
1618

19+
use const JSON_THROW_ON_ERROR;
20+
1721
final class Parser implements ParserInterface
1822
{
1923
private Decoder $decoder;
@@ -105,7 +109,9 @@ private function parseClaims(string $data): array
105109
continue;
106110
}
107111

108-
$claims[$claim] = $this->convertDate((string) $claims[$claim]);
112+
$date = $claims[$claim];
113+
114+
$claims[$claim] = $this->convertDate(is_string($date) ? $date : json_encode($date, JSON_THROW_ON_ERROR));
109115
}
110116

111117
return $claims;

test/unit/Encoding/ChainedFormatterTest.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,6 @@ public function formatClaimsShouldApplyAllConfiguredFormatters(): void
3434
$formatted = $formatter->formatClaims($claims);
3535

3636
self::assertSame('test', $formatted[RegisteredClaims::AUDIENCE]);
37-
self::assertSame('1487285080.123456', $formatted[RegisteredClaims::EXPIRATION_TIME]);
37+
self::assertSame(1487285080.123456, $formatted[RegisteredClaims::EXPIRATION_TIME]);
3838
}
3939
}

test/unit/Encoding/MicrosecondBasedDateConversionTest.php

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,8 @@ public function dateClaimsHaveMicrosecondsOrSeconds(): void
3636
$formatted = $formatter->formatClaims($claims);
3737

3838
self::assertSame(1487285080, $formatted[RegisteredClaims::ISSUED_AT]);
39-
self::assertSame('1487285080.000123', $formatted[RegisteredClaims::NOT_BEFORE]);
40-
self::assertSame('1487285080.123456', $formatted[RegisteredClaims::EXPIRATION_TIME]);
39+
self::assertSame(1487285080.000123, $formatted[RegisteredClaims::NOT_BEFORE]);
40+
self::assertSame(1487285080.123456, $formatted[RegisteredClaims::EXPIRATION_TIME]);
4141
self::assertSame('test', $formatted['testing']); // this should remain untouched
4242
}
4343

@@ -62,7 +62,7 @@ public function notAllDateClaimsNeedToBeConfigured(): void
6262
$formatted = $formatter->formatClaims($claims);
6363

6464
self::assertSame(1487285080, $formatted[RegisteredClaims::ISSUED_AT]);
65-
self::assertSame('1487285080.123456', $formatted[RegisteredClaims::EXPIRATION_TIME]);
65+
self::assertSame(1487285080.123456, $formatted[RegisteredClaims::EXPIRATION_TIME]);
6666
self::assertSame('test', $formatted['testing']); // this should remain untouched
6767
}
6868
}

test/unit/Token/ParserTest.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -453,7 +453,7 @@ public function parseMustConvertDateClaimsToObjects(): void
453453
{
454454
$data = [
455455
RegisteredClaims::ISSUED_AT => 1486930663,
456-
RegisteredClaims::EXPIRATION_TIME => '1486930757.023055',
456+
RegisteredClaims::EXPIRATION_TIME => 1486930757.023055,
457457
];
458458

459459
$this->decoder->expects(self::exactly(2))

0 commit comments

Comments
 (0)