Sandor Molnar created KNOX-3480:
-----------------------------------

             Summary: Support user-supplied clientId in the Client Credentials 
endpoint
                 Key: KNOX-3480
                 URL: https://issues.apache.org/jira/browse/KNOX-3480
             Project: Apache Knox
          Issue Type: Task
          Components: JWT, Server
    Affects Versions: 3.0.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 3.1.0


Today {{{}clientid/api/v1/oauth/credentials }} always returns a 
server-generated UUID as {{client_id{}}}, which is stored as 
{{{}KNOX_TOKENS.token_id{}}}. Well-known IdPs (Auth0, Okta, Keycloak) let the 
caller choose the client identifier at registration. Add the same capability to 
Knox.

When the caller supplies a {{clientId}} query param, use that value as the 
token's {{knox.id/token_id}} instead of a generated UUID. When omitted, 
behavior is unchanged (random UUID). Uniqueness is backed by the 
{{KNOX_TOKENS.token_id}} primary key.

Scope / implementation:
 - Read optional clientId param in {{{}ClientCredentialsResource{}}}; thread it 
down through TokenResource.getJWT() → JWTokenAttributes(Builder) → JWTToken so 
the {{knox.id}} claim uses the supplied value (fall back to UUID.randomUUID()).
 - Reject collisions explicitly (pre-check via TokenStateService) — do not 
depend on the DB PK, since the in-memory store overwrites silently.
 - Validate the supplied value: non-blank, length ≤128, restricted charset.

Acceptance criteria:
 - clientId supplied → response client_id equals it, and it is the token_id row 
/ passcode-auth works.
 - clientId omitted → unchanged UUID behavior.
 - Duplicate clientId → clear client error (not 500, not silent overwrite).
 - Invalid clientId (too long / bad chars) → clear client error.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to