coheigea opened a new pull request, #3518:
URL: https://github.com/apache/cxf/pull/3518
Add opt-in issuer and audience-presence checks to the JWT authentication
filter, and enforce the RFC 7523 "aud" requirement in the OAuth2 JWT
bearer handlers.
AbstractJwtAuthenticationFilter (JwtAuthenticationFilter):
- New "supportedIssuers" property, mirroring
AbstractJwtHandler.setSupportedIssuers. When set, the token must carry
an "iss" claim contained in the set; an empty set rejects all tokens.
Overridable via protected validateIssuer(String).
- New "requireAudience" property. When true, a token without an "aud"
claim is rejected. Previously such a token passed the audience
restriction check unless JwtConstants.EXPECTED_CLAIM_AUDIENCE was
configured. Overridable via protected validateAudiencePresent(List).
- Both checks are off by default, so existing deployments are unaffected.
-
JwtBearerAuthHandler and AbstractJwtHandler (JwtBearerGrantHandler):
- Reject assertions without an "aud" claim with invalid_grant, as
required by RFC 7523 section 3, alongside the existing iss/sub/exp
checks. JwtBearerAuthHandler skips the check when validateAudience is
disabled.
- This is enforced by default: clients or issuers sending JWT bearer
assertions without "aud" will now be rejected.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]