Colm O hEigeartaigh created CXF-9252:
----------------------------------------
Summary: Enforce audience validation on some CXF Oauth2 filters
Key: CXF-9252
URL: https://issues.apache.org/jira/browse/CXF-9252
Project: CXF
Issue Type: Improvement
Reporter: Colm O hEigeartaigh
Assignee: Colm O hEigeartaigh
Fix For: 4.3.0
# *{{JwtAccessTokenValidator.requireAudience}} → {{{}true{}}}.* RFC 9068 says
JWT access tokens MUST contain {{aud}} and resource servers MUST validate it,
so a JWT _access token_ validator accepting tokens without {{aud}} goes against
the spec. The cost is breaking authorization servers that don't issue
{{{}aud{}}}, and they can set the flag back to {{{}false{}}}. I'd leave
{{AbstractJwtAuthenticationFilter}} at {{{}false{}}}: it handles general JWTs,
not only access tokens, and wrong-audience tokens are already rejected.
# *{{{}OAuthRequestFilter{}}}: fail at startup unless an audience is
configured or checking is explicitly turned off.* Requiring {{aud}} to be
present doesn't bind anything, as you pointed out, because the filter can't
guess its own audience. The only default that actually secures it is making the
integrator choose: {{{}audience{}}}, {{{}audienceIsEndpointAddress{}}}, or
something like {{{}setValidateAudience(false){}}}. That breaks every resource
server that has none configured, so it only belongs in a major release, with
the warning in this patch as the step before.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)