[ 
https://issues.apache.org/jira/browse/KNOX-3480?focusedWorklogId=1043543&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1043543
 ]

ASF GitHub Bot logged work on KNOX-3480:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 23/Sep/26 12:22
            Start Date: 23/Sep/26 12:22
    Worklog Time Spent: 10m 
      Work Description: smolnar82 commented on code in PR #1422:
URL: https://github.com/apache/knox/pull/1422#discussion_r4082343958


##########
gateway-server/src/main/java/org/apache/knox/gateway/services/token/impl/JDBCTokenStateService.java:
##########
@@ -119,6 +121,9 @@ public void addToken(String tokenId, long issueTime, long 
expiration, long maxLi
       }
     } catch (SQLException e) {
       log.errorSavingTokenInDatabase(Tokens.getTokenIDDisplayText(tokenId), 
e.getMessage(), e);
+      if (JDBCUtils.isUniqueConstraintViolation(e)) {

Review Comment:
   Good idea; I fix that.





Issue Time Tracking
-------------------

    Worklog Id:     (was: 1043543)
    Time Spent: 1h 20m  (was: 1h 10m)

> Support user-supplied clientId in the Client Credentials endpoint
> -----------------------------------------------------------------
>
>                 Key: KNOX-3480
>                 URL: https://issues.apache.org/jira/browse/KNOX-3480
>             Project: Apache Knox
>          Issue Type: Task
>          Components: JWT, Server
>    Affects Versions: 3.0.0
>            Reporter: Sandor Molnar
>            Assignee: Sandor Molnar
>            Priority: Major
>             Fix For: 3.1.0
>
>          Time Spent: 1h 20m
>  Remaining Estimate: 0h
>
> Today {{{}clientid/api/v1/oauth/credentials }} always returns a 
> server-generated UUID as {{client_id{}}}, which is stored as 
> {{{}KNOX_TOKENS.token_id{}}}. Well-known IdPs (Auth0, Okta, Keycloak) let the 
> caller choose the client identifier at registration. Add the same capability 
> to Knox.
> When the caller supplies a {{clientId}} query param, use that value as the 
> token's {{knox.id/token_id}} instead of a generated UUID. When omitted, 
> behavior is unchanged (random UUID). Uniqueness is backed by the 
> {{KNOX_TOKENS.token_id}} primary key.
> Scope / implementation:
>  - Read optional clientId param in {{{}ClientCredentialsResource{}}}; thread 
> it down through TokenResource.getJWT() → JWTokenAttributes(Builder) → 
> JWTToken so the {{knox.id}} claim uses the supplied value (fall back to 
> UUID.randomUUID()).
>  - Reject collisions explicitly (pre-check via TokenStateService) — do not 
> depend on the DB PK, since the in-memory store overwrites silently.
>  - Validate the supplied value: non-blank, length ≤128, restricted charset.
> Acceptance criteria:
>  - clientId supplied → response client_id equals it, and it is the token_id 
> row / passcode-auth works.
>  - clientId omitted → unchanged UUID behavior.
>  - Duplicate clientId → clear client error (not 500, not silent overwrite).
>  - Invalid clientId (too long / bad chars) → clear client error.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to