Colm O hEigeartaigh created CXF-9252:
----------------------------------------

             Summary: Enforce audience validation on some CXF Oauth2 filters
                 Key: CXF-9252
                 URL: https://issues.apache.org/jira/browse/CXF-9252
             Project: CXF
          Issue Type: Improvement
            Reporter: Colm O hEigeartaigh
            Assignee: Colm O hEigeartaigh
             Fix For: 4.3.0


# *{{JwtAccessTokenValidator.requireAudience}} → {{{}true{}}}.* RFC 9068 says 
JWT access tokens MUST contain {{aud}} and resource servers MUST validate it, 
so a JWT _access token_ validator accepting tokens without {{aud}} goes against 
the spec. The cost is breaking authorization servers that don't issue 
{{{}aud{}}}, and they can set the flag back to {{{}false{}}}. I'd leave 
{{AbstractJwtAuthenticationFilter}} at {{{}false{}}}: it handles general JWTs, 
not only access tokens, and wrong-audience tokens are already rejected.
 # *{{{}OAuthRequestFilter{}}}: fail at startup unless an audience is 
configured or checking is explicitly turned off.* Requiring {{aud}} to be 
present doesn't bind anything, as you pointed out, because the filter can't 
guess its own audience. The only default that actually secures it is making the 
integrator choose: {{{}audience{}}}, {{{}audienceIsEndpointAddress{}}}, or 
something like {{{}setValidateAudience(false){}}}. That breaks every resource 
server that has none configured, so it only belongs in a major release, with 
the warning in this patch as the step before.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to