[ 
https://issues.apache.org/jira/browse/SYNCOPE-217?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jan Bernhardt updated SYNCOPE-217:
----------------------------------

    Description: 
public boolean hasTokenExpired() {
        return tokenExpireTime.before(new Date());
}

should be changed to:

public boolean hasTokenExpired() {
        return tokenExpireTime == null
                ? false
                : tokenExpireTime.before(new Date());
}

A token set to null should never expire to be consistent with the behavior that 
a token will always be vaild valid (in checkToken method) if it is null.

  was:
public boolean hasTokenExpired() {
        return tokenExpireTime.before(new Date());
}

should be changed to:

public boolean hasTokenExpired() {
        return tokenExpireTime != null && tokenExpireTime.before(new Date());
}

A token set to null should never expire to be consistent with the behavior that 
a token will always be vaild valid (in checkToken method) if it is null.

    
> hasTokenExpired check for syncope user can easily cause nullpointer exception
> -----------------------------------------------------------------------------
>
>                 Key: SYNCOPE-217
>                 URL: https://issues.apache.org/jira/browse/SYNCOPE-217
>             Project: Syncope
>          Issue Type: Bug
>          Components: core
>    Affects Versions: 1.1.0-incubating
>            Reporter: Jan Bernhardt
>            Priority: Minor
>
> public boolean hasTokenExpired() {
>         return tokenExpireTime.before(new Date());
> }
> should be changed to:
> public boolean hasTokenExpired() {
>         return tokenExpireTime == null
>                 ? false
>                 : tokenExpireTime.before(new Date());
> }
> A token set to null should never expire to be consistent with the behavior 
> that a token will always be vaild valid (in checkToken method) if it is null.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Reply via email to