Package org.keycloak.protocol.oidc.utils
Class ClientHostUtils
java.lang.Object
org.keycloak.protocol.oidc.utils.ClientHostUtils
Utility class for validating client host values against a client's registered URLs.
Used to prevent SSRF attacks by ensuring that dynamic host values (like client_session_host)
only reference hosts that are already configured and trusted for the client.
The trust model is: an administrator configures/opts in to create a client policy with the
secure-client-node-hostname executor. This gates the register-node write
endpoint against an admin-curated regex allowlist. Hostnames that pass that gate are stored
in registeredNodes. This utility therefore treats registeredNodes as a
pre-validated set and uses it (together with the management URL) as the source of allowed
hosts for dynamic values such as client_session_host.
Resolves [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionstatic StringformatAsUriHost(String host) static booleanisHostAllowedForClient(String hostname, ClientModel client, KeycloakSession session) Validates that a hostname matches one of the client's registered nodes or the host component of the administrator-configured management URL.
-
Constructor Details
-
ClientHostUtils
public ClientHostUtils()
-
-
Method Details
-
isHostAllowedForClient
public static boolean isHostAllowedForClient(String hostname, ClientModel client, KeycloakSession session) Validates that a hostname matches one of the client's registered nodes or the host component of the administrator-configured management URL.Registered nodes are trusted here; if the
secure-client-node-hostnameexecutor is active, hostnames will have been validated at registration time.- Parameters:
hostname- the hostname (orhost:port) to validateclient- the client model containing registered nodes and management URLsession- the Keycloak session used for relative URL resolution- Returns:
trueif the hostname matches a registered node or the management URL host,falseotherwise
-
formatAsUriHost
-