[ 
https://issues.apache.org/jira/browse/CAMEL-25486?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18125371#comment-18125371
 ] 

Claus Ibsen commented on CAMEL-25486:
-------------------------------------

PR: https://github.com/apache/camel/pull/27601

_Claude Code on behalf of davsclaus_

> camel-http - the OAuth2 token request with a resource indicator sends only 
> the resource parameter
> -------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25486
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25486
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-http
>            Reporter: Claus Ibsen
>            Assignee: Claus Ibsen
>            Priority: Major
>             Fix For: 4.23.0
>
>
> When the camel-http OAuth2 client credentials flow is configured with a 
> resource indicator (the oauth2ResourceIndicator option, RFC 8707, added in 
> CAMEL-21712), the token request body only contains the resource parameter.
> OAuth2ClientConfigurer.getAccessTokenResponse builds the body as 
> "grant_type=client_credentials", then "&scope=...", then (with 
> oauth2BodyAuthentication) "&client_id=...&client_secret=...", and then does:
> {code:java}
> bodyStr = String.join(bodyStr, "&resource=" + resourceIndicator);
> {code}
> String.join(delimiter, elements...) with a single element returns that 
> element, so the body becomes just "&resource=<value>": grant_type, scope and 
> the client credentials sent in the body are dropped. A token endpoint then 
> rejects the request (no grant_type), so the oauth2ResourceIndicator option 
> does not work at all.
> The fix is to append the parameter: bodyStr += "&resource=" + 
> resourceIndicator. No test covered the resource indicator.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to