Harrison Sheinblatt created KNOX-3491:
-----------------------------------------

             Summary: Allow JWT aud validation against request header values 
and include an initial delegation token only validator
                 Key: KNOX-3491
                 URL: https://issues.apache.org/jira/browse/KNOX-3491
             Project: Apache Knox
          Issue Type: Sub-task
          Components: JWT
            Reporter: Harrison Sheinblatt


Extend JWT aud claim validation to allow for custom validators that require the 
request parameter so they can validate against the destination from headers. 
Retain the existing default that validates aud claims against a fixed, 
configured allow list.

Add a validator implementation that can validate delegation JWTs, those with an 
act claim, for kubernetes environments. aud claim values in such tokens were 
already authorized via delegation policy which can include allowed audience 
lists. This validation restricts those tokens so that they can be used only for 
k8s destinations that match. Provide flexibility in the headers used and enable 
partial matching of the aud claim so that parts of the destination can be used 
to validate the aud claim. This allows one to validate what can be validated in 
more different k8s configurations, even if all the destination information is 
not available via trusted headers.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to