cxf-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Colm O hEigeartaigh (JIRA)" <>
Subject [jira] [Commented] (CXF-7110) Inflexible jwt audience restriction validation
Date Wed, 26 Oct 2016 14:07:58 GMT


Colm O hEigeartaigh commented on CXF-7110:

For SAML there is a property:

     * Enable SAML AudienceRestriction validation. If this is set to "true", then IF the
     * SAML Token contains Audience Restriction URIs, one of them must match either the
     * request URL or the Service QName. The default is "true".
    public static final String AUDIENCE_RESTRICTION_VALIDATION = "security.validate.audience-restriction";

We could probably add something similar for JWT.

> Inflexible jwt audience restriction validation
> ----------------------------------------------
>                 Key: CXF-7110
>                 URL:
>             Project: CXF
>          Issue Type: Improvement
>          Components: JAX-RS Security
>    Affects Versions: 3.1.7
>         Environment: JVM 1.7, Ubuntu 14
>            Reporter: Shaleen Mishra
> JwtUtils.validateJwtAudienceRestriction checks the audience url matches the current request
url (from the context). This works only during development but is most likely to fail because
the actual url of the resource server may be behind the proxy or load balancer etc. e.g. The
actual request is sent to and the requester sends this string in the audience
parameter but the server actually serving the request may have a url like localhost:8080/oauth.
So the match fails. And thanks to the static util function, it can not be customized easily.

This message was sent by Atlassian JIRA

View raw message