Skip to content

fix(state): treat non-object and oversized-integer JSON as malformed state - #381

Merged
allen0099 merged 1 commit into
masterfrom
fix/368-state-non-object-json
Sep 29, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/368-state-non-object-json

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Fixes #368.

StateManager._decode_state let two kinds of malformed stored state escape as the wrong exception:

  • JSON that is not an object ([1, 2], "x", 1, null): StateData(**...) raised TypeError, and only ValueError was caught.
  • An integer longer than sys.int_info.default_max_str_digits (4300 by default), top-level or nested: json.loads raised a plain ValueError, and only JSONDecodeError was caught.

Both now raise StateDataError, so the three public methods behave as documented for malformed data: validate_state() returns False, get_state_metadata() returns None, and consume_state() raises StateDataError (the entry is deleted, as before).

The non-object case is checked with isinstance(..., dict) after json.loads rather than by also catching TypeError, so the error names the problem and an unrelated TypeError from the model is not swallowed. The oversized-integer case came up while reviewing this fix.

Tests

  • Parametrized tests for each of the three methods with the four non-object values, and one covering the oversized integer (top-level and nested). Without the fix, all of them fail.
  • The full suite passes with the Redis and Memcached tests enabled.
  • Changelog fragment: changelog.d/368.fixed.md.

…state

_decode_state caught only ValueError around StateData(**...) and only
JSONDecodeError around json.loads, so a stored state that was JSON but not
an object escaped as TypeError, and one holding an integer past the
interpreter's digit limit escaped as ValueError. validate_state,
get_state_metadata and consume_state now treat both as malformed data.

Fixes #368
@allen0099 allen0099 added bug Something isn't working oauth-state StateManager: one-time OAuth state tokens labels Sep 29, 2026
@allen0099
allen0099 merged commit 6101f59 into master Sep 29, 2026
12 checks passed
@allen0099
allen0099 deleted the fix/368-state-non-object-json branch September 29, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working oauth-state StateManager: one-time OAuth state tokens

Projects

None yet

Development

Successfully merging this pull request may close these issues.

StateManager: a stored state that is JSON but not an object raises TypeError instead of StateDataError

1 participant