janhoy commented on code in PR #890:
URL: https://github.com/apache/solr/pull/890#discussion_r969555443


##########
solr/modules/jwt-auth/src/java/org/apache/solr/security/jwt/JWTAuthPlugin.java:
##########
@@ -598,12 +599,48 @@ protected JWTAuthenticationResponse authenticate(String 
authorizationHeader) {
             } else {
               // Pull roles from separate claim, either as whitespace 
separated list or as JSON
               // array
-              Object rolesObj = jwtClaims.getClaimValue(rolesClaim);
+              Object rolesObj;
+              if (rolesClaim.indexOf('.') > 0) {

Review Comment:
   The case where an access token contains both a `foo.bar` and a `foo: { bar 
}` entry is so narrow that I think it blurs more than it clarifies to add it to 
the docs. I hope this behaviour follows the least surprise rule. You are free 
to suggest re-wording of the docs though..



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to