Nicola Scendoni created SLING-13315:
---------------------------------------
Summary: OidcAuthenticationHandler: make JWK set retrieval HTTP
limits configurable (large JWK set fails ID token validation)
Key: SLING-13315
URL: https://issues.apache.org/jira/browse/SLING-13315
Project: Sling
Issue Type: Improvement
Components: Extensions
Reporter: Nicola Scendoni
h4. Problem
ID token validation in {{OidcAuthenticationHandler}} fails when the IdP's
{{jwks_uri}} returns a JWK set larger than 50 KB. The error seen in the logs is:
{noformat}
*ERROR* org.apache.sling.auth.oauth_client.impl.OidcAuthenticationHandler
Failed to validate token: Couldn't retrieve remote JWK set: Exceeded configured
input limit of 51200 bytes
com.nimbusds.jose.RemoteKeySourceException: Couldn't retrieve remote JWK set:
Exceeded configured input limit of 51200 bytes
{noformat}
h4. Root cause
{{validateIdToken(...)}} builds the validator with the constructor that relies
on
Nimbus' default {{DefaultResourceRetriever}}:
{code:java}
IDTokenValidator validator = new IDTokenValidator(issuer, clientID, jwsAlg,
jwkSetURL);
{code}
That default retriever hard-codes {{RemoteJWKSet.DEFAULT_HTTP_SIZE_LIMIT = 50 *
1024}}
(51200 bytes), along with 500 ms connect/read timeouts. There is no way to
raise these
from an OSGi configuration, so an IdP that publishes a large key set (many
rotated keys
or large x5c certificate chains) cannot be used.
Nimbus does expose a JVM system property
({{com.nimbusds.jose.jwk.source.RemoteJWKSet.defaultHttpSizeLimit}}), but that
is a
JVM-global setting and is not available in restricted/managed deployments where
arbitrary
{{-D}} flags cannot be set.
h4. Proposed fix
Add three OSGi configuration attributes to the handler and pass an explicitly
configured
{{DefaultResourceRetriever}} to the {{IDTokenValidator}}:
* {{jwkSetHttpSizeLimit}} (default 51200) — max JWK set size in bytes, 0 =
unlimited
* {{jwkSetHttpConnectTimeout}} (default 500) — connect timeout in ms, 0 = no
timeout
* {{jwkSetHttpReadTimeout}} (default 500) — read timeout in ms, 0 = no timeout
{code:java}
DefaultResourceRetriever resourceRetriever =
new DefaultResourceRetriever(jwkSetHttpConnectTimeout,
jwkSetHttpReadTimeout, jwkSetHttpSizeLimit);
IDTokenValidator validator =
new IDTokenValidator(issuer, clientID, jwsAlg, jwkSetURL,
resourceRetriever);
{code}
Defaults match the current Nimbus values, so existing deployments are
unaffected unless
the values are explicitly overridden.
h4. Notes
Also removes the standing {{// TODO specify HTTP response limits}} concern in
the JWK
retrieval path. A PR with unit tests (verifying a too-small limit fails and a
raised
limit succeeds) can be provided.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)