[ 
https://issues.apache.org/jira/browse/KNOX-3478?focusedWorklogId=1043736&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1043736
 ]

ASF GitHub Bot logged work on KNOX-3478:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 24/Sep/26 13:23
            Start Date: 24/Sep/26 13:23
    Worklog Time Spent: 10m 
      Work Description: pzampino commented on code in PR #1425:
URL: https://github.com/apache/knox/pull/1425#discussion_r4094045675


##########
gateway-service-auth/src/main/java/org/apache/knox/gateway/service/auth/AbstractAuthResource.java:
##########
@@ -56,13 +62,65 @@ public abstract class AbstractAuthResource {
 
   static final Pattern DEFAULT_GROUP_FILTER_PATTERN = Pattern.compile(".*");
 
+  /*
+   * Bounds this one header only it is not a budget for the whole response, 
whose group headers
+   * are unbounded by default (see GROUP_HEADER_SIZE_LIMIT). Jetty caps the 
response headers at
+   * gateway.httpserver.responseHeaderBuffer (8KB by default) and the calling 
proxy has a limit of
+   * its own, so 6KB is a token size that still leaves room for the status 
line, the standard
+   * headers and this service's actor id header.
+   */
+  private static final String DEFAULT_AUTH_TOKEN_SIZE_LIMIT = "6144";

Review Comment:
   Do we expect tokens to be this large?





Issue Time Tracking
-------------------

    Worklog Id:     (was: 1043736)
    Time Spent: 1h 10m  (was: 1h)

> Extend auth service API to pass JWT token as header downstream
> --------------------------------------------------------------
>
>                 Key: KNOX-3478
>                 URL: https://issues.apache.org/jira/browse/KNOX-3478
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>            Reporter: Sandeep More
>            Assignee: Sandeep More
>            Priority: Major
>          Time Spent: 1h 10m
>  Remaining Estimate: 0h
>
> There could be cases where we might need to pass user authenticated tokens to 
> be passed down to the downstream applications along side `
> preauth.auth.header.actor.id.name` and 
> `preauth.auth.header.actor.groups.prefix`



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to