Sandor Molnar created KNOX-3458:
-----------------------------------
Summary: Enforce a maximum actor-chain (act claim) depth in token
exchange
Key: KNOX-3458
URL: https://issues.apache.org/jira/browse/KNOX-3458
Project: Apache Knox
Issue Type: Sub-task
Components: Server
Affects Versions: 3.1.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.1.0
The RFC 8693 act claim chain is walked and rebuilt with no depth bound
anywhere: {{TokenUtils.extractActorChain()}}, {{addActorToChain()}}, and
{{buildNestedActClaim()}} all iterate unbounded, and
{{ActorChainPrincipalImpl}} does no validation. A deeply nested act claim can
grow without limit across successive delegation exchanges.
Scope: Add a configurable maximum chain depth (e.g.
{{delegation.max.actor.chain.depth}}) and enforce it at the point the chain is
about to grow - TokenResource.handleDelegatedAuthentication() /
TokenUtils.addActorToChain() (last chance before minting), rejecting the
exchange when the resulting depth would exceed the bound. Default to 10.
Note: {{TokenExchangeHandler.auditMessage()}} already lists {{act_chain_depth}}
as a deliberately-omitted field. Audit it once enforced.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)