Claus Ibsen created CAMEL-25486:
-----------------------------------

             Summary: camel-http - the OAuth2 token request with a resource 
indicator sends only the resource parameter
                 Key: CAMEL-25486
                 URL: https://issues.apache.org/jira/browse/CAMEL-25486
             Project: Camel
          Issue Type: Bug
          Components: camel-http
            Reporter: Claus Ibsen
             Fix For: 4.23.0


When the camel-http OAuth2 client credentials flow is configured with a 
resource indicator (the oauth2ResourceIndicator option, RFC 8707, added in 
CAMEL-21712), the token request body only contains the resource parameter.

OAuth2ClientConfigurer.getAccessTokenResponse builds the body as 
"grant_type=client_credentials", then "&scope=...", then (with 
oauth2BodyAuthentication) "&client_id=...&client_secret=...", and then does:

{code:java}
bodyStr = String.join(bodyStr, "&resource=" + resourceIndicator);
{code}

String.join(delimiter, elements...) with a single element returns that element, 
so the body becomes just "&resource=<value>": grant_type, scope and the client 
credentials sent in the body are dropped. A token endpoint then rejects the 
request (no grant_type), so the oauth2ResourceIndicator option does not work at 
all.

The fix is to append the parameter: bodyStr += "&resource=" + 
resourceIndicator. No test covered the resource indicator.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to