oscerd opened a new pull request, #26893:
URL: https://github.com/apache/camel/pull/26893

   ## What
   
   When `OAuthBearerTokenProcessor` authenticates an access token through the 
Jakarta servlet backend
   (`ServletOAuth`), `UserProfile` validated the JWS signature and the issuer, 
and `UserProfile.expired()`
   evaluated `exp`, but the `nbf` (not before) claim was only copied into the 
profile attributes and never
   evaluated. RFC 7519 section 4.1.5 specifies that a JWT must not be accepted 
for processing before its `nbf`
   time. The Vert.x backend (through Vert.x `User.expired(leeway)`) and the 
`OAuthTokenValidationFactory` SPI
   (`JwtTokenValidator`) already evaluate `nbf`.
   
   ## Changes
   
   - `UserProfile.verifyToken()` — reject a token whose `nbf` is later than the 
current time plus the leeway
     configured in `JWTOptions` (`getLeeway()`, default `0`, the same default 
as the Vert.x backend and the SPI
     `clock-skew-seconds` option). Tokens without an `nbf` claim are unaffected.
   - Upgrade guide (4.23) — note under camel-oauth.
   
   ## Tests
   
   - `UserProfileTest` — a token with a future `nbf` is rejected, a token whose 
`nbf` has passed is accepted,
     and the configured leeway is honored (accepted within it, rejected beyond 
it).
   - `ServletOAuthTokenCredentialsTest` (new) — the servlet bearer path, 
`ServletOAuth.authenticate(TokenCredentials)`,
     rejects a token before its `nbf` and accepts it afterwards, without 
contacting an identity provider.
   - The new tests fail when the check is removed, and when the leeway is 
ignored.
   - `mvn clean install` in `components/camel-oauth`: 141 tests, 0 failures 
(the 7 skipped are the existing
     Keycloak-environment tests). Full reactor `mvn clean install -DskipTests 
-DskipITs`: green.
   
   The backports to `camel-4.22.x` and `camel-4.18.x` will follow once this is 
merged, together with the matching
   4.22 / 4.18 upgrade-guide notes on main.
   
   JIRA: https://issues.apache.org/jira/browse/CAMEL-25022
   
   _Claude Code on behalf of oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to