Andrea Cosentino created CAMEL-24456:
----------------------------------------

             Summary: camel-http - OAuth2 token cache key omits tokenEndpoint, 
scope and resourceIndicator
                 Key: CAMEL-24456
                 URL: https://issues.apache.org/jira/browse/CAMEL-24456
             Project: Camel
          Issue Type: Bug
          Components: camel-http
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino
             Fix For: 4.23.0


{{OAuth2ClientConfigurer}} holds a {{private final static 
ConcurrentMap<OAuth2URIAndCredentials, TokenCache> tokenCache}}, keyed by the 
record {{OAuth2URIAndCredentials(URI uri, String clientId, String 
clientSecret)}}.

{{scope}}, {{tokenEndpoint}} and {{resourceIndicator}} all influence the token 
that gets minted, but none of them are part of the key. The map is static, so 
it is shared across every {{OAuth2ClientConfigurer}} instance and every 
{{CamelContext}} in the JVM.

A route configured with a narrow scope can therefore be handed a broad-scope 
token that another route cached first, which defeats the scoping the operator 
configured and makes the audit trail misleading. Where several 
{{CamelContext}}s run in one JVM, a token minted for one can serve another's 
requests.

Proposal: include {{tokenEndpoint}}, {{scope}} and {{resourceIndicator}} in the 
cache key. Scoping the cache per {{CamelContext}} rather than per JVM would be 
worth considering at the same time.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to