oscerd opened a new pull request, #26893:
URL: https://github.com/apache/camel/pull/26893
## What
When `OAuthBearerTokenProcessor` authenticates an access token through the
Jakarta servlet backend
(`ServletOAuth`), `UserProfile` validated the JWS signature and the issuer,
and `UserProfile.expired()`
evaluated `exp`, but the `nbf` (not before) claim was only copied into the
profile attributes and never
evaluated. RFC 7519 section 4.1.5 specifies that a JWT must not be accepted
for processing before its `nbf`
time. The Vert.x backend (through Vert.x `User.expired(leeway)`) and the
`OAuthTokenValidationFactory` SPI
(`JwtTokenValidator`) already evaluate `nbf`.
## Changes
- `UserProfile.verifyToken()` — reject a token whose `nbf` is later than the
current time plus the leeway
configured in `JWTOptions` (`getLeeway()`, default `0`, the same default
as the Vert.x backend and the SPI
`clock-skew-seconds` option). Tokens without an `nbf` claim are unaffected.
- Upgrade guide (4.23) — note under camel-oauth.
## Tests
- `UserProfileTest` — a token with a future `nbf` is rejected, a token whose
`nbf` has passed is accepted,
and the configured leeway is honored (accepted within it, rejected beyond
it).
- `ServletOAuthTokenCredentialsTest` (new) — the servlet bearer path,
`ServletOAuth.authenticate(TokenCredentials)`,
rejects a token before its `nbf` and accepts it afterwards, without
contacting an identity provider.
- The new tests fail when the check is removed, and when the leeway is
ignored.
- `mvn clean install` in `components/camel-oauth`: 141 tests, 0 failures
(the 7 skipped are the existing
Keycloak-environment tests). Full reactor `mvn clean install -DskipTests
-DskipITs`: green.
The backports to `camel-4.22.x` and `camel-4.18.x` will follow once this is
merged, together with the matching
4.22 / 4.18 upgrade-guide notes on main.
JIRA: https://issues.apache.org/jira/browse/CAMEL-25022
_Claude Code on behalf of oscerd_
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]