[
https://issues.apache.org/jira/browse/KNOX-3423?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Tamás Hanicz updated KNOX-3423:
-------------------------------
Description:
RFC 8693 §2.2.2 and RFC 6749 §5.2 require JSON error bodies (\{{{}
{"error":..., "error_description":...} for token exchange requests. The
existing format would break any standards-compliant client. Non-token-exchange
paths (normal JWT bearer authentication) use plain text by design and must not
be changed.
was:RFC 8693 §2.2.2 and RFC 6749 §5.2 require JSON error bodies
({{{}{"error":..., "error_description":...}{}}}) for token exchange requests.
The existing format would break any standards-compliant client.
Non-token-exchange paths (normal JWT bearer authentication) use plain text by
design and must not be changed.
> Switch to JSON error messages in Knox token validation paths
> ------------------------------------------------------------
>
> Key: KNOX-3423
> URL: https://issues.apache.org/jira/browse/KNOX-3423
> Project: Apache Knox
> Issue Type: Improvement
> Components: Server
> Affects Versions: 3.1.0
> Reporter: Tamás Hanicz
> Assignee: Tamás Hanicz
> Priority: Major
>
> RFC 8693 §2.2.2 and RFC 6749 §5.2 require JSON error bodies (\{{{}
> {"error":..., "error_description":...} for token exchange requests. The
> existing format would break any standards-compliant client.
> Non-token-exchange paths (normal JWT bearer authentication) use plain text by
> design and must not be changed.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)