[ 
https://issues.apache.org/jira/browse/CAMEL-24281?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino resolved CAMEL-24281.
--------------------------------------
    Resolution: Fixed

Fixed on main via PR https://github.com/apache/camel/pull/25187. 
Platform-http-main JWT authentication now fails closed when the token has no 
issuer/audience and validation is configured; the opt-out flag 
jwtAllowMissingIssuerAndAudience (marked security=insecure:dev) restores the 
previous accept-signature-and-expiry-only behavior. Main-only (4.22.0) as it 
changes a security default.

_Claude Code on behalf of Andrea Cosentino (@oscerd)._

> camel-platform-http-main: fail closed when JWT authentication is enabled 
> without an issuer or audience
> ------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24281
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24281
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-platform-http
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.22.0
>
>
> When JWT authentication is enabled on the camel-main embedded HTTP server, 
> {{JWTAuthenticationConfigurer.buildJwtOptions(...)}} returns {{null}} if 
> neither {{jwtIssuer}} nor {{jwtAudience}} is configured, and the caller then 
> skips {{JWTAuthOptions.setJWTOptions(...)}}. The resulting Vert.x {{JWTAuth}} 
> is built from the keystore alone, so only the token signature and the {{exp}} 
> / {{nbf}} claims are enforced and the {{iss}} and {{aud}} claims are not.
> Nothing signals this to the user: the setup completes normally and the server 
> starts, so a deployment that configures JWT authentication the documented way 
> can be enforcing less than intended.
> Proposal: fail closed at startup when a JWT keystore is configured but 
> neither {{jwtIssuer}} nor {{jwtAudience}} is set, with an explicit opt-out 
> for deployments that genuinely want signature and expiry only validation. The 
> check must be applied to both overloads of {{configureAuthentication}}, since 
> the application server and the management server share this configurer.
> This aligns the embedded server with the posture already used by 
> {{camel-oauth}}, where 
> {{DefaultOAuthTokenValidationFactory.validateResolvedConfiguration}} refuses 
> to operate unless an expected audience and issuer are configured 
> ({{allow-missing-audience}} and {{allow-missing-issuer}} both default to 
> {{false}}).
> Notes:
> * {{jwtIssuer}} and {{jwtAudience}} were added in 4.21.0 by CAMEL-23525, so 
> this only applies to branches that have those options.
> * Add tests covering the fail-closed path and the opt-out, and an 
> upgrade-guide note, since this changes startup behaviour for an existing 
> configuration.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to