[
https://issues.apache.org/jira/browse/CAMEL-24319?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino updated CAMEL-24319:
-------------------------------------
Fix Version/s: 4.22.0
> camel-keycloak: optional token type (typ) and authorized party (azp)
> validation in KeycloakSecurityPolicy
> ---------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24319
> URL: https://issues.apache.org/jira/browse/CAMEL-24319
> Project: Camel
> Issue Type: Improvement
> Components: camel-keycloak
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.22.0
>
>
> KeycloakSecurityPolicy verifies token signature, issuer and active state,
> plus optional audience validation (CAMEL-23875), but does not check the
> token's type (typ) or authorized party (azp).
> This adds two opt-in settings, mirroring the existing expectedAudience opt-in
> and applied on both the local JWT verification path and the token
> introspection path:
> * expectedTokenTypes - a comma-separated allow-list of accepted typ values
> (e.g. "Bearer"). Guards against token-type confusion, for example an ID token
> or refresh token being presented where an access token is expected.
> * expectedAuthorizedParty - the expected azp value (e.g. "my-client");
> ensures the token was issued for the expected client.
> Both checks are disabled by default for backward compatibility
> (non-breaking). Includes unit tests and documentation.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)