cxf-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Diarmuid Power (JIRA)" <j...@apache.org>
Subject [jira] [Created] (CXF-5227) OAuthRequestFilter should respond with a 401 exception when no token is supplied.
Date Thu, 22 Aug 2013 14:51:51 GMT
Diarmuid Power created CXF-5227:
-----------------------------------

             Summary: OAuthRequestFilter should respond with a 401 exception when no token
is supplied.
                 Key: CXF-5227
                 URL: https://issues.apache.org/jira/browse/CXF-5227
             Project: CXF
          Issue Type: Bug
          Components: JAX-RS Security
    Affects Versions: 2.7.6
            Reporter: Diarmuid Power
            Priority: Minor


The OAuthRequestFilter, encounters an unhandled exception when no oAuth token is provided.
The following line of code throws a _javax.ws.rs.NotAuthorizedException_

{code}
AccessTokenValidation accessTokenV = getAccessTokenValidation();
{code}
org.apache.cxf.rs.security.oauth2.filters.OAuthRequestFilter.filter()

I think that the filter should instead catch this exception and then rethrow an exception
that will yield an appropriate error code such as

{code}
throw new WebApplicationException( 401 );
{code}

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira

Mime
View raw message