Harrison Sheinblatt created KNOX-3461:
-----------------------------------------
Summary: Same subject validation for requested audience
Key: KNOX-3461
URL: https://issues.apache.org/jira/browse/KNOX-3461
Project: Apache Knox
Issue Type: Sub-task
Components: JWT
Reporter: Harrison Sheinblatt
When delegation is enabled, we'll want to set the knoxidf audience strategy to
passthrough so we rely on the delegation policy to authorize a requested
audience instead of the hardcoded list. But once that's set, then the
same-subject requested audience is unauthorized at all. So we either need to
not allow requested audiences just for same-subject exchanges with a setting,
or add enforcement, or both.
The simplest thing is to add a setting to skip reading the requested audience
only for same-subject token exchanges.
The natural authz is to validate the original subject token has the audience
requested to allow the requested audience. So if the flag to allow reading the
audience for same-subject exchange is on, we'd authorize on the subject token.
If this proves a problem, we can turn it off or figure out a way to add more
audiences to the user tokens knox issues.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)