angela created OAK-4224:
---------------------------

             Summary: DefaultSyncContext.sync(ExternalIdentity) should verify 
IDP
                 Key: OAK-4224
                 URL: https://issues.apache.org/jira/browse/OAK-4224
             Project: Jackrabbit Oak
          Issue Type: Bug
          Components: auth-external
            Reporter: angela
            Priority: Minor


while writing more test for {{DefaultSyncContext}} i realized that the 
implementation of {{sync(ExternalIdentity)}} doesn't verify that the given 
external identity belongs to the same IDP than the one associated with the 
context instance.

IMHO this would be needed and useful particularly when multiple IDPs are 
combined. also, the  {{DefaultSyncContext}} is a public exposed class, I would 
prefer if it would guard against mixing up sync of external identities from 
different sources.





--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to