moresandeep commented on code in PR #1425:
URL: https://github.com/apache/knox/pull/1425#discussion_r4094115438


##########
gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java:
##########
@@ -56,13 +62,65 @@ public abstract class AbstractAuthResource {
 
   static final Pattern DEFAULT_GROUP_FILTER_PATTERN = Pattern.compile(".*");
 
+  /*
+   * Bounds this one header only it is not a budget for the whole response, 
whose group headers
+   * are unbounded by default (see GROUP_HEADER_SIZE_LIMIT). Jetty caps the 
response headers at
+   * gateway.httpserver.responseHeaderBuffer (8KB by default) and the calling 
proxy has a limit of
+   * its own, so 6KB is a token size that still leaves room for the status 
line, the standard
+   * headers and this service's actor id header.
+   */
+  private static final String DEFAULT_AUTH_TOKEN_SIZE_LIMIT = "6144";

Review Comment:
   We have had cases where JWT tokens were huge, this can be because they can 
include assertions, groups etc! 
   This is configurable.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to