This is an automated email from the ASF dual-hosted git repository. smolnar82 pushed a commit to branch knox_idf in repository https://gitbox.apache.org/repos/asf/knox.git
commit 34d403040e77b9003fce8d01a2726637ce297005 Author: Sandor Molnar <[email protected]> AuthorDate: Wed Aug 12 00:48:10 2026 +0200 KNOX-3414: document the UUIDv5 namespace used for federated subject derivation The hardcoded KNOX_NAMESPACE UUID is the RFC 4122 "URL" namespace constant, not a random value. Add a comment explaining that it is the fixed namespace for deriving a stable Knox 'sub' (UUIDv5) from a federated identity's issuer+subject, that determinism across logins/restarts is the intent, and that it must not change once identities are persisted. Comment only; no behavior change. Co-Authored-By: Claude Opus 4.8 <[email protected]> --- .../org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java index d2a12b581..4fedca83e 100644 --- a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java +++ b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java @@ -116,6 +116,11 @@ import static org.apache.knox.gateway.util.knoxidf.KnoxIDFUtils.error; @Path(AuthorizeResource.RESOURCE_PATH) public class AuthorizeResource extends PasscodeTokenResourceBase { static final String RESOURCE_PATH = BASE_RESOURCE_PATH + "/authorize"; + // RFC 4122 "URL" namespace UUID. Used as the fixed namespace for deriving a STABLE Knox + // subject (UUIDv5) from a federated identity's issuer+subject (see deriveKnoxSubject), so the + // same upstream user always maps to the same Knox 'sub' across logins and gateway restarts. + // Must not change once federated identities are persisted -- it would rewrite every existing + // federated user's subject. private static final UUID KNOX_NAMESPACE = UUID.fromString("6ba7b811-9dad-11d1-80b4-00c04fd430c8"); private static final NameBasedGenerator UUID_V5 = Generators.nameBasedGenerator(KNOX_NAMESPACE); public static final Set<String> ALLOWED_CLAIMS = Set.of("preferred_username", "email", "email_verified",
