Harrison Sheinblatt created KNOX-3461:
-----------------------------------------

             Summary: Same subject validation for requested audience
                 Key: KNOX-3461
                 URL: https://issues.apache.org/jira/browse/KNOX-3461
             Project: Apache Knox
          Issue Type: Sub-task
          Components: JWT
            Reporter: Harrison Sheinblatt


When delegation is enabled, we'll want to set the knoxidf audience strategy to 
passthrough so we rely on the delegation policy to authorize a requested 
audience instead of the hardcoded list. But once that's set, then the 
same-subject requested audience is unauthorized at all. So we either need to 
not allow requested audiences just for same-subject exchanges with a setting, 
or add enforcement, or both. 

The simplest thing is to add a setting to skip reading the requested audience 
only for same-subject token exchanges.

The natural authz is to validate the original subject token has the audience 
requested to allow the requested audience. So if the flag to allow reading the 
audience for same-subject exchange is on, we'd authorize on the subject token. 
If this proves a problem, we can turn it off or figure out a way to add more 
audiences to the user tokens knox issues.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to