davsclaus commented on code in PR #26893: URL: https://github.com/apache/camel/pull/26893#discussion_r4112510188
########## docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc: ########## @@ -1844,6 +1844,18 @@ identity provider. Note that `nonce` and PKCE (`code_challenge`) are still not sent, and the session cookie is still `SameSite=None; Secure`. +=== camel-oauth + +The Jakarta servlet backend (`ServletOAuth`) now evaluates the `nbf` (not before) claim of the tokens it +validates, and rejects a token before that time as RFC 7519 section 4.1.5 requires. This covers the bearer +token that `OAuthBearerTokenProcessor` authenticates as well as the tokens received from the identity +provider. Previously only `exp` was evaluated, so a token was accepted before its `nbf` time. + +The comparison allows for the leeway configured on the `JWTOptions` of the OAuth configuration, which Review Comment: On the servlet backend nothing sets this leeway from configuration: `ServletOAuth.discoverOAuthConfig` only sets the issuer on `JWTOptions`, and `clock-skew-seconds` is SPI-only. Could you add how users can raise it (e.g. `getOAuthConfig().getJWTOptions().setLeeway(n)`) for providers whose clock runs ahead and which issue `nbf == iat`? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
