This is an automated email from the ASF dual-hosted git repository.
smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git
The following commit(s) were added to refs/heads/knox_idf by this push:
new 3a4239c6d KNOX-3414: fix refresh-token rotation dropping the rotated
refresh_token
3a4239c6d is described below
commit 3a4239c6de97334dac01c1fe694a9edb5abeabab
Author: Sandor Molnar <[email protected]>
AuthorDate: Thu Aug 13 18:48:14 2026 +0200
KNOX-3414: fix refresh-token rotation dropping the rotated refresh_token
buildResponseMap gated id_token + refresh-token issuance behind
isAuthCodeFlow() only, but the refresh_token grant also flows through it,
so token rotation stopped returning a new refresh_token. Run that block
for both authorization_code and refresh_token grants, still excluding
client_credentials.
Co-Authored-By: Claude Opus 4.8 <[email protected]>
---
.../org/apache/knox/gateway/service/knoxidf/TokenResource.java | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
index 0171c9f74..9aaf371e1 100644
---
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
+++
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
@@ -156,6 +156,10 @@ public class TokenResource extends
PasscodeTokenResourceBase {
return AUTH_CODE.equals(grantType);
}
+ private boolean isRefreshTokenFlow() {
+ return REFRESH_TOKEN.equals(getRequestParam(GRANT_TYPE));
+ }
+
@Override
protected UserContext buildUserContext(HttpServletRequest request) {
if (isAuthCodeFlow()) {
@@ -200,7 +204,10 @@ public class TokenResource extends
PasscodeTokenResourceBase {
protected ResponseMap buildResponseMap(JWT token, long expires) throws
TokenServiceException {
final ResponseMap responseMap = super.buildResponseMap(token, expires);
- if (isAuthCodeFlow()) {
+ // id_token + refresh-token rotation apply to the user-centric grants
(authorization_code and
+ // refresh_token). client_credentials and other grants routed to
super.doPost() must not get an
+ // id_token (no end user) and never carry offline_access, so they are
excluded here.
+ if (isAuthCodeFlow() || isRefreshTokenFlow()) {
final String code = getRequestParam(CODE);
TokenMetadata authCodeTokenMetadata = null;
if (StringUtils.isNotBlank(code)) {