[
https://issues.apache.org/jira/browse/CAMEL-25486?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18125371#comment-18125371
]
Claus Ibsen commented on CAMEL-25486:
-------------------------------------
PR: https://github.com/apache/camel/pull/27601
_Claude Code on behalf of davsclaus_
> camel-http - the OAuth2 token request with a resource indicator sends only
> the resource parameter
> -------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25486
> URL: https://issues.apache.org/jira/browse/CAMEL-25486
> Project: Camel
> Issue Type: Bug
> Components: camel-http
> Reporter: Claus Ibsen
> Assignee: Claus Ibsen
> Priority: Major
> Fix For: 4.23.0
>
>
> When the camel-http OAuth2 client credentials flow is configured with a
> resource indicator (the oauth2ResourceIndicator option, RFC 8707, added in
> CAMEL-21712), the token request body only contains the resource parameter.
> OAuth2ClientConfigurer.getAccessTokenResponse builds the body as
> "grant_type=client_credentials", then "&scope=...", then (with
> oauth2BodyAuthentication) "&client_id=...&client_secret=...", and then does:
> {code:java}
> bodyStr = String.join(bodyStr, "&resource=" + resourceIndicator);
> {code}
> String.join(delimiter, elements...) with a single element returns that
> element, so the body becomes just "&resource=<value>": grant_type, scope and
> the client credentials sent in the body are dropped. A token endpoint then
> rejects the request (no grant_type), so the oauth2ResourceIndicator option
> does not work at all.
> The fix is to append the parameter: bodyStr += "&resource=" +
> resourceIndicator. No test covered the resource indicator.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)