coheigea opened a new pull request, #3518:
URL: https://github.com/apache/cxf/pull/3518

   Add opt-in issuer and audience-presence checks to the JWT authentication
   filter, and enforce the RFC 7523 "aud" requirement in the OAuth2 JWT
   bearer handlers.
   
   AbstractJwtAuthenticationFilter (JwtAuthenticationFilter):
   - New "supportedIssuers" property, mirroring
     AbstractJwtHandler.setSupportedIssuers. When set, the token must carry
     an "iss" claim contained in the set; an empty set rejects all tokens.
     Overridable via protected validateIssuer(String).
   - New "requireAudience" property. When true, a token without an "aud"
     claim is rejected. Previously such a token passed the audience
     restriction check unless JwtConstants.EXPECTED_CLAIM_AUDIENCE was
     configured. Overridable via protected validateAudiencePresent(List).
   - Both checks are off by default, so existing deployments are unaffected.
   - 
   JwtBearerAuthHandler and AbstractJwtHandler (JwtBearerGrantHandler):
   - Reject assertions without an "aud" claim with invalid_grant, as
     required by RFC 7523 section 3, alongside the existing iss/sub/exp
     checks. JwtBearerAuthHandler skips the check when validateAudience is
     disabled.
   - This is enforced by default: clients or issuers sending JWT bearer
     assertions without "aud" will now be rejected.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to