Claus Ibsen created CAMEL-25486:
-----------------------------------
Summary: camel-http - the OAuth2 token request with a resource
indicator sends only the resource parameter
Key: CAMEL-25486
URL: https://issues.apache.org/jira/browse/CAMEL-25486
Project: Camel
Issue Type: Bug
Components: camel-http
Reporter: Claus Ibsen
Fix For: 4.23.0
When the camel-http OAuth2 client credentials flow is configured with a
resource indicator (the oauth2ResourceIndicator option, RFC 8707, added in
CAMEL-21712), the token request body only contains the resource parameter.
OAuth2ClientConfigurer.getAccessTokenResponse builds the body as
"grant_type=client_credentials", then "&scope=...", then (with
oauth2BodyAuthentication) "&client_id=...&client_secret=...", and then does:
{code:java}
bodyStr = String.join(bodyStr, "&resource=" + resourceIndicator);
{code}
String.join(delimiter, elements...) with a single element returns that element,
so the body becomes just "&resource=<value>": grant_type, scope and the client
credentials sent in the body are dropped. A token endpoint then rejects the
request (no grant_type), so the oauth2ResourceIndicator option does not work at
all.
The fix is to append the parameter: bodyStr += "&resource=" +
resourceIndicator. No test covered the resource indicator.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)