Skip to content

Fix ISO8601Utils#parse time zone validation - #3131

Open
Marcono1234 wants to merge 2 commits into
google:mainfrom
Marcono1234:marcono1234/fix-iso-date-parsing
Open

Marcono1234 wants to merge 2 commits into
google:mainfrom
Marcono1234:marcono1234/fix-iso-date-parsing

Conversation

@Marcono1234

Copy link
Copy Markdown
Contributor

Purpose

Description

As mentioned in #3111 there is a bug in the current ISO8601Utils#parse implementation when a short time zone such as +00 is extended to +0000, causing the parsing end offset to be incorrect.
This had previously no visible effect for users because Gson did not validate the parsing end offset.

It also fixes that trailing data after the time zone indicator Z was not rejected.

*/
public static Date parseFully(String dateStr) throws ParseException {
ParsePosition pos = new ParsePosition(0);
Date date = ISO8601Utils.parse(dateStr, pos);
* @see <a href="http://www.w3.org/TR/NOTE-datetime">this specification</a>
*/
// Date parsing code from Jackson databind ISO8601Utils.java
// Date parsing code from Jackson databind ISO8601Utils.java, with modifications

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just added this as clarification; the code already contained Gson-specific modifications before, see Git history

Comment on lines +245 to +247
if (date.length() > offset) {
throw new IllegalArgumentException("Trailing data after time zone 'Z'");
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alternative would be to remove this check here again and let it fail in parseFully instead.

(It seems in all other cases trailing invalid data is already rejected.)

@Marcono1234
Marcono1234 marked this pull request as ready for review September 30, 2026 11:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants