[
https://issues.apache.org/jira/browse/KNOX-3491?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120867#comment-18120867
]
ASF subversion and git services commented on KNOX-3491:
-------------------------------------------------------
Commit a9e27337864cc6025b4eaf6603c77d5bde98f895 in knox's branch
refs/heads/master from hsheinblatt
[ https://gitbox.apache.org/repos/asf?p=knox.git;h=a9e273378 ]
KNOX-3491 - Add pluggable request audience validation, with a Kubernetes
destination validator (#1432)
> Allow JWT aud validation against request header values and include an initial
> delegation token only validator
> -------------------------------------------------------------------------------------------------------------
>
> Key: KNOX-3491
> URL: https://issues.apache.org/jira/browse/KNOX-3491
> Project: Apache Knox
> Issue Type: Sub-task
> Components: JWT
> Reporter: Harrison Sheinblatt
> Priority: Major
> Time Spent: 1h 20m
> Remaining Estimate: 0h
>
> Extend JWT aud claim validation to allow for custom validators that require
> the request parameter so they can validate against the destination from
> headers. Retain the existing default that validates aud claims against a
> fixed, configured allow list.
> Add a validator implementation that can validate delegation JWTs, those with
> an act claim, for kubernetes environments. aud claim values in such tokens
> were already authorized via delegation policy which can include allowed
> audience lists. This validation restricts those tokens so that they can be
> used only for k8s destinations that match. Provide flexibility in the headers
> used and enable partial matching of the aud claim so that parts of the
> destination can be used to validate the aud claim. This allows one to
> validate what can be validated in more different k8s configurations, even if
> all the destination information is not available via trusted headers.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)