[
https://issues.apache.org/jira/browse/KNOX-3458?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18115821#comment-18115821
]
Harrison Sheinblatt commented on KNOX-3458:
-------------------------------------------
I'd consider a lower bound than 10, that can cause a lot of problems in agentic
cases. Looking at vendors, they mostly default to 1, but some default to 5. I
was thinking 3 makes sense for agentic flows, it gives you a chance to have the
main agent, subagent, and tool. I could imagine 4 or 5 if we want to allow for
gateways in between subagent and tool and perhaps the tool calling another
service. It's configurable, so it shouldn't matter too much, but 10 seems risky
as a default. Best to pick a conservative value like 1 or 3 and let the
operator tune that up if they want to.
> Enforce a maximum actor-chain (act claim) depth in token exchange
> -----------------------------------------------------------------
>
> Key: KNOX-3458
> URL: https://issues.apache.org/jira/browse/KNOX-3458
> Project: Apache Knox
> Issue Type: Sub-task
> Components: Server
> Affects Versions: 3.1.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Major
> Fix For: 3.1.0
>
> Time Spent: 0.5h
> Remaining Estimate: 0h
>
> The RFC 8693 act claim chain is walked and rebuilt with no depth bound
> anywhere: {{TokenUtils.extractActorChain()}}, {{addActorToChain()}}, and
> {{buildNestedActClaim()}} all iterate unbounded, and
> {{ActorChainPrincipalImpl}} does no validation. A deeply nested act claim can
> grow without limit across successive delegation exchanges.
> Scope: Add a configurable maximum chain depth (e.g.
> {{delegation.max.actor.chain.depth}}) and enforce it at the point the chain
> is about to grow - TokenResource.handleDelegatedAuthentication() /
> TokenUtils.addActorToChain() (last chance before minting), rejecting the
> exchange when the resulting depth would exceed the bound. Default to 10.
> Note: {{TokenExchangeHandler.auditMessage()}} already lists
> {{act_chain_depth}} as a deliberately-omitted field. Audit it once enforced.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)