| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
…ower cased in ASCII only, independently of the default locale, incorporating github PR #2485.
|
maybe Locale.ROOT would be more appropriate? |
Sorry, something went wrong.
|
They fold identically: the only locale-specific case rules are the tr, az and lt ones, and a run over every code point shows no difference between Locale.ROOT and Locale.ENGLISH for toLowerCase or toUpperCase. I kept Locale.ENGLISH because Locale.ROOT is 1.6+ and this class also ships in bcmail-jdk15to18, which runs on Java 5, and because it's what the rest of the tree uses for these comparisons (HostnameUtil, BCSNIHostName, DisabledAlgorithmConstraints). Nothing in the tree uses Locale.ROOT today. |
Sorry, something went wrong.
|
Thanks for the PR! This has merged with some changes, principally it was modified to use Strings.toLowerCase() which only affects ascii characters and ignores the Locale, this felt like it better met the original intention of the patch. Result is now up on https://www.bouncycastle.org/betas let us know how it goes. |
Sorry, something went wrong.
|
thanks for merging this. Strings.toLowerCase() is the better fit, ascii-only is all these addresses need and it takes the locale out of the picture entirely rather than pinning one. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
SignedMailValidator folds both sides of the comparison that ties a signature to the sender the message claims, the certificate's email addresses in getEmailAddresses and the From addresses in hasAnyFromAddress, with Locale.getDefault() captured in a static field at class load, so on a Turkish or Azerbaijani JVM I lower cases to the dotless ı and a legitimately signed message is reported as emailFromCertMismatch while a certificate whose emailAddress attribute carries U+0130 (the attribute is read through ASN1String, not restricted to IA5String) folds onto a different mailbox and satisfies the check for it; found sweeping every module's src/main for case conversion used in a security comparison, which turned up this as the only default-locale one, the JSSE HostnameUtil, BCSNIHostName and DisabledAlgorithmConstraints all fixing Locale.ENGLISH and the EST hostname authorizer using the locale-independent Strings.toLowerCase.
AI tooling was used to help prepare this change.