Andrea Cosentino created CAMEL-24497:
----------------------------------------

             Summary: camel-undertow-spring-security-starter - JWT decoder is 
built without an issuer or audience validator
                 Key: CAMEL-24497
                 URL: https://issues.apache.org/jira/browse/CAMEL-24497
             Project: Camel
          Issue Type: Improvement
          Components: camel-spring-boot-starters, camel-undertow
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino


{{UndertowSpringSecurityCustomizer.jwtDecoderByIssuerUri()}} builds the decoder 
from the JWK set URI and installs only a claim-set converter:

{code:java}
@Bean
public JwtDecoder jwtDecoderByIssuerUri() {
    final String jwkSetUri = 
getClientRegistration().getProviderDetails().getJwkSetUri();
    final NimbusJwtDecoder jwtDecoder = 
NimbusJwtDecoder.withJwkSetUri(jwkSetUri).build();
    jwtDecoder.setClaimSetConverter(new 
KeycloakUsernameSubClaimAdapter(getProvider().getUserNameAttribute()));
    return jwtDecoder;
}
{code}

(UndertowSpringSecurityCustomizer:107)

Despite the bean name, the decoder is built with {{withJwkSetUri}} and no 
{{setJwtValidator}} call, so the default validator applies: signature and 
timestamps are checked, but the {{iss}} claim is not, and the configured 
{{clientId}} is used only to build the {{ClientRegistration}} and is never 
bound to an {{aud}}/{{azp}} check. Spring Security's own {{withIssuerLocation}} 
path installs an issuer validator by default; this starter's construction path 
does not.

*Proposal*

{code:java}
jwtDecoder.setJwtValidator(new DelegatingOAuth2TokenValidator<>(
        JwtValidators.createDefaultWithIssuer(issuerUri),
        new AudienceValidator(getClientRegistration().getClientId())));
{code}

with the issuer derived from the configured {{url}} + {{realmId}}.

Separately: the starter has no test module, and the registration of the 
non-static inner {{@EnableWebSecurity SecurityConfiguration}} is not confirmed 
anywhere. A test asserting that the security filter chain actually installs 
would be worth adding alongside, since the decoder bean is only reached if the 
chain is registered.

----
_This issue was drafted by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to