Repository navigation
Fix ClassCastException in RAR schema validation for integer keywords - #8324
Conversation
Gson parses every number of a Map<String, Object> as a Double, so integer schema keywords such as minItems and maxItems were returned as 1.0/3.0. JSON schema validators like Vert.x cast these keywords directly to Integer, causing a ClassCastException during RAR authorization_details validation. Add parseSchemaForValidation, which returns integral numbers as Integer (or Long when out of Integer range), and use it for schemas loaded for authorization details validation. parseSchema and the API resource management responses remain unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: wso2/carbon-identity-framework/.coderabbit.yml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe change adds a validation-specific schema parser that preserves integral values as integers when possible. Authorization-details type construction now uses this parser. Tests cover the new parser and confirm the existing parser behavior. ChangesSchema validation parsing
Priority: ⬇️ Low Change: Bug fix Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is established for the schema parsing change; it is ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change is narrowly scoped and does not establish a new access path or weaker authorization control. Downstream compatibility and error handling remain unverified, so some uncertainty remains. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Description checkExplanation The description explains the problem, implementation approach, affected code path, and related issue. However, it omits most required template sections, including Goals, User stories, Release note, Documentation, Training, Certification, Marketing, Automation tests, Security checks, Samples, Related PRs, Migrations, Test environment, and Learning. Full details: Docstring CoverageExplanation Docstring coverage is 60.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 3 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #8324 +/- ##
============================================
+ Coverage 53.65% 53.68% +0.03%
+ Complexity 22647 22621 -26
============================================
Files 2264 2264
Lines 138114 138125 +11
Branches 23871 23873 +2
============================================
+ Hits 74100 74155 +55
+ Misses 55083 55039 -44
Partials 8931 8931
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|



Purpose
Validating
authorization_detailsagainst a registered schema that usesminItems/maxItems(and similar integer keywords) fails withClassCastException: Double cannot be cast to Integer, regardless of the payload.AuthorizationDetailsTypesUtil.parseSchemauses a defaultGson, which parses every number in aMap<String, Object>as aDouble. The Vert.x JSON schema validator used by the OAuth RAR component castsminItems,maxItems,minProperties,maxProperties,minContainsandmaxContainsdirectly toInteger.Approach
AuthorizationDetailsTypesUtil.parseSchemaForValidation, which parses schemas with aToNumberStrategythat returns integral values (including ones written as1.0) asInteger. Values outside theIntegerrange and non-integral numbers are returned asLong/Double.AuthorizedAPIDAOImpl.getAuthorizedAuthorizationDetailsTypes, the read path that supplies schemas to RAR validation (DefaultAuthorizationDetailsValidator).parseSchemais unchanged, so the API resource management responses keep their current format. No new configuration is introduced.Related issues
🤖 Generated with Claude Code