[ 
https://issues.apache.org/jira/browse/KNOX-3491?focusedWorklogId=1044341&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1044341
 ]

ASF GitHub Bot logged work on KNOX-3491:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 28/Sep/26 10:34
            Start Date: 28/Sep/26 10:34
    Worklog Time Spent: 10m 
      Work Description: smolnar82 commented on code in PR #1432:
URL: https://github.com/apache/knox/pull/1432#discussion_r4121062710


##########
gateway-provider-security-jwt/src/main/java/org/apache/knox/gateway/provider/federation/jwt/filter/JWTFederationFilter.java:
##########
@@ -177,6 +177,16 @@ public enum TokenType {
   // Handles RFC 8693 token exchange requests (see doFilter).
   private TokenExchangeHandler tokenExchangeHandler = new 
TokenExchangeHandler(this);
 
+  // Discovers a RequestAudienceValidator by name (see 
RequestAudienceValidatorService's
+  // REQUEST_AUDIENCE_VALIDATOR_PARAM) for this filter's own direct-bearer JWT 
path.
+  private final RequestAudienceValidatorService 
requestAudienceValidatorService = new RequestAudienceValidatorService();

Review Comment:
   nit: this shouldn't be a class member. It can be created in the init() 
method and use as a simple variable in a method.



##########
gateway-provider-security-jwt/src/main/java/org/apache/knox/gateway/provider/federation/jwt/filter/AudienceValidationResult.java:
##########
@@ -0,0 +1,44 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.knox.gateway.provider.federation.jwt.filter;
+
+/**
+ * Outcome of a {@link RequestAudienceValidator} check: whether the request's
+ * token satisfies the audience requirement, and an optional message.
+ */
+public final class AudienceValidationResult {

Review Comment:
   nit: this could be a `record` too.





Issue Time Tracking
-------------------

    Worklog Id:     (was: 1044341)
    Time Spent: 20m  (was: 10m)

> Allow JWT aud validation against request header values and include an initial 
> delegation token only validator
> -------------------------------------------------------------------------------------------------------------
>
>                 Key: KNOX-3491
>                 URL: https://issues.apache.org/jira/browse/KNOX-3491
>             Project: Apache Knox
>          Issue Type: Sub-task
>          Components: JWT
>            Reporter: Harrison Sheinblatt
>            Priority: Major
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> Extend JWT aud claim validation to allow for custom validators that require 
> the request parameter so they can validate against the destination from 
> headers. Retain the existing default that validates aud claims against a 
> fixed, configured allow list.
> Add a validator implementation that can validate delegation JWTs, those with 
> an act claim, for kubernetes environments. aud claim values in such tokens 
> were already authorized via delegation policy which can include allowed 
> audience lists. This validation restricts those tokens so that they can be 
> used only for k8s destinations that match. Provide flexibility in the headers 
> used and enable partial matching of the aud claim so that parts of the 
> destination can be used to validate the aud claim. This allows one to 
> validate what can be validated in more different k8s configurations, even if 
> all the destination information is not available via trusted headers.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to