coheigea commented on code in PR #3530:
URL: https://github.com/apache/cxf/pull/3530#discussion_r4146174969
##########
rt/rs/security/oauth-parent/oauth2/src/main/java/org/apache/cxf/rs/security/oauth2/filters/JwtAccessTokenValidator.java:
##########
@@ -51,6 +51,7 @@ public class JwtAccessTokenValidator extends JoseJwtConsumer
implements AccessTo
private Map<String, String> jwtAccessTokenClaimMap;
private boolean validateAudience = true;
+ private boolean requireAudience;
Review Comment:
Yes, requireAudience only takes effect when validateAudience is enabled (the
default). Both flags go into JwtUtils.validateTokenClaims, and requireAudience
just decides what happens in the "no aud claim" branch of the audience
restriction check, which isn't reached when validateAudience is false. So:
- validateAudience=true, requireAudience=false (defaults): a token without
aud is accepted; if aud is present it must match the expected audience or the
request URL.
- validateAudience=true, requireAudience=true: a token without aud is
rejected; otherwise same as above.
- validateAudience=false: no audience checks at all, whatever
requireAudience is set to.
I went with this because validateAudience=false is an explicit opt-out of
audience validation, and it keeps the semantics the same as
JwtBearerAuthHandler and JwtAuthenticationFilter
([#3518](https://github.com/apache/cxf/pull/3518)). It's noted in the
setRequireAudience Javadoc.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]