This is an automated email from the ASF dual-hosted git repository.

smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git

commit 34d403040e77b9003fce8d01a2726637ce297005
Author: Sandor Molnar <[email protected]>
AuthorDate: Wed Aug 12 00:48:10 2026 +0200

    KNOX-3414: document the UUIDv5 namespace used for federated subject 
derivation
    
    The hardcoded KNOX_NAMESPACE UUID is the RFC 4122 "URL" namespace constant,
    not a random value. Add a comment explaining that it is the fixed namespace
    for deriving a stable Knox 'sub' (UUIDv5) from a federated identity's
    issuer+subject, that determinism across logins/restarts is the intent, and
    that it must not change once identities are persisted. Comment only; no
    behavior change.
    
    Co-Authored-By: Claude Opus 4.8 <[email protected]>
---
 .../org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java   | 5 +++++
 1 file changed, 5 insertions(+)

diff --git 
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java
 
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java
index d2a12b581..4fedca83e 100644
--- 
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java
+++ 
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/AuthorizeResource.java
@@ -116,6 +116,11 @@ import static 
org.apache.knox.gateway.util.knoxidf.KnoxIDFUtils.error;
 @Path(AuthorizeResource.RESOURCE_PATH)
 public class AuthorizeResource extends PasscodeTokenResourceBase {
     static final String RESOURCE_PATH = BASE_RESOURCE_PATH + "/authorize";
+    // RFC 4122 "URL" namespace UUID. Used as the fixed namespace for deriving 
a STABLE Knox
+    // subject (UUIDv5) from a federated identity's issuer+subject (see 
deriveKnoxSubject), so the
+    // same upstream user always maps to the same Knox 'sub' across logins and 
gateway restarts.
+    // Must not change once federated identities are persisted -- it would 
rewrite every existing
+    // federated user's subject.
     private static final UUID KNOX_NAMESPACE = 
UUID.fromString("6ba7b811-9dad-11d1-80b4-00c04fd430c8");
     private static final NameBasedGenerator UUID_V5 = 
Generators.nameBasedGenerator(KNOX_NAMESPACE);
     public static final Set<String> ALLOWED_CLAIMS = 
Set.of("preferred_username", "email", "email_verified",

Reply via email to