davsclaus commented on code in PR #26893:
URL: https://github.com/apache/camel/pull/26893#discussion_r4112510188


##########
docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc:
##########
@@ -1844,6 +1844,18 @@ identity provider.
 Note that `nonce` and PKCE (`code_challenge`) are still not sent, and the 
session cookie is still
 `SameSite=None; Secure`.
 
+=== camel-oauth
+
+The Jakarta servlet backend (`ServletOAuth`) now evaluates the `nbf` (not 
before) claim of the tokens it
+validates, and rejects a token before that time as RFC 7519 section 4.1.5 
requires. This covers the bearer
+token that `OAuthBearerTokenProcessor` authenticates as well as the tokens 
received from the identity
+provider. Previously only `exp` was evaluated, so a token was accepted before 
its `nbf` time.
+
+The comparison allows for the leeway configured on the `JWTOptions` of the 
OAuth configuration, which

Review Comment:
   On the servlet backend nothing sets this leeway from configuration: 
`ServletOAuth.discoverOAuthConfig` only sets the issuer on `JWTOptions`, and 
`clock-skew-seconds` is SPI-only. Could you add how users can raise it (e.g. 
`getOAuthConfig().getJWTOptions().setLeeway(n)`) for providers whose clock runs 
ahead and which issue `nbf == iat`?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to