This is an automated email from the ASF dual-hosted git repository.

smolnar82 pushed a commit to branch knox_idf
in repository https://gitbox.apache.org/repos/asf/knox.git


The following commit(s) were added to refs/heads/knox_idf by this push:
     new 3a4239c6d KNOX-3414: fix refresh-token rotation dropping the rotated 
refresh_token
3a4239c6d is described below

commit 3a4239c6de97334dac01c1fe694a9edb5abeabab
Author: Sandor Molnar <[email protected]>
AuthorDate: Thu Aug 13 18:48:14 2026 +0200

    KNOX-3414: fix refresh-token rotation dropping the rotated refresh_token
    
    buildResponseMap gated id_token + refresh-token issuance behind
    isAuthCodeFlow() only, but the refresh_token grant also flows through it,
    so token rotation stopped returning a new refresh_token. Run that block
    for both authorization_code and refresh_token grants, still excluding
    client_credentials.
    
    Co-Authored-By: Claude Opus 4.8 <[email protected]>
---
 .../org/apache/knox/gateway/service/knoxidf/TokenResource.java   | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git 
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
 
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
index 0171c9f74..9aaf371e1 100644
--- 
a/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
+++ 
b/gateway-service-knoxidf/src/main/java/org/apache/knox/gateway/service/knoxidf/TokenResource.java
@@ -156,6 +156,10 @@ public class TokenResource extends 
PasscodeTokenResourceBase {
         return AUTH_CODE.equals(grantType);
     }
 
+    private boolean isRefreshTokenFlow() {
+        return REFRESH_TOKEN.equals(getRequestParam(GRANT_TYPE));
+    }
+
     @Override
     protected UserContext buildUserContext(HttpServletRequest request) {
         if (isAuthCodeFlow()) {
@@ -200,7 +204,10 @@ public class TokenResource extends 
PasscodeTokenResourceBase {
     protected ResponseMap buildResponseMap(JWT token, long expires) throws 
TokenServiceException {
         final ResponseMap responseMap = super.buildResponseMap(token, expires);
 
-        if (isAuthCodeFlow()) {
+        // id_token + refresh-token rotation apply to the user-centric grants 
(authorization_code and
+        // refresh_token). client_credentials and other grants routed to 
super.doPost() must not get an
+        // id_token (no end user) and never carry offline_access, so they are 
excluded here.
+        if (isAuthCodeFlow() || isRefreshTokenFlow()) {
             final String code = getRequestParam(CODE);
             TokenMetadata authCodeTokenMetadata = null;
             if (StringUtils.isNotBlank(code)) {

Reply via email to