oscerd commented on code in PR #26893:
URL: https://github.com/apache/camel/pull/26893#discussion_r4122355372


##########
docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc:
##########
@@ -1844,6 +1844,18 @@ identity provider.
 Note that `nonce` and PKCE (`code_challenge`) are still not sent, and the 
session cookie is still
 `SameSite=None; Secure`.
 
+=== camel-oauth
+
+The Jakarta servlet backend (`ServletOAuth`) now evaluates the `nbf` (not 
before) claim of the tokens it
+validates, and rejects a token before that time as RFC 7519 section 4.1.5 
requires. This covers the bearer
+token that `OAuthBearerTokenProcessor` authenticates as well as the tokens 
received from the identity
+provider. Previously only `exp` was evaluated, so a token was accepted before 
its `nbf` time.
+
+The comparison allows for the leeway configured on the `JWTOptions` of the 
OAuth configuration, which

Review Comment:
   Thanks, you're right. `ServletOAuth.discoverOAuthConfig` only sets the 
issuer, so on the servlet backend the leeway is always `0`, and 
`clock-skew-seconds` feeds only the incoming token validation SPI 
(`DefaultOAuthTokenValidationFactory`), not `UserProfile`.
   
   Done in 8eade5a. The guide now says that, and shows how to raise the leeway 
on the `OAuth` instance:
   
   ```java
   OAuthFactory factory = OAuthFactory.lookupFactory(camelContext);
   OAuth oauth = factory.findOAuth().orElseGet(factory::createOAuth);
   oauth.getOAuthConfig().getJWTOptions().setLeeway(30);
   ```
   
   `findOAuth().orElseGet(factory::createOAuth)` mirrors what 
`OAuthBearerTokenProcessor` does on its first request, so the processor then 
picks up the same instance with the raised leeway.
   
   _Claude Code on behalf of @oscerd_
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to