Harrison Sheinblatt created KNOX-3491:
-----------------------------------------
Summary: Allow JWT aud validation against request header values
and include an initial delegation token only validator
Key: KNOX-3491
URL: https://issues.apache.org/jira/browse/KNOX-3491
Project: Apache Knox
Issue Type: Sub-task
Components: JWT
Reporter: Harrison Sheinblatt
Extend JWT aud claim validation to allow for custom validators that require the
request parameter so they can validate against the destination from headers.
Retain the existing default that validates aud claims against a fixed,
configured allow list.
Add a validator implementation that can validate delegation JWTs, those with an
act claim, for kubernetes environments. aud claim values in such tokens were
already authorized via delegation policy which can include allowed audience
lists. This validation restricts those tokens so that they can be used only for
k8s destinations that match. Provide flexibility in the headers used and enable
partial matching of the aud claim so that parts of the destination can be used
to validate the aud claim. This allows one to validate what can be validated in
more different k8s configurations, even if all the destination information is
not available via trusted headers.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)