[
https://issues.apache.org/jira/browse/CXF-9236?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Guanping Zhang updated CXF-9236:
--------------------------------
Environment: Apache CXF 3.6.10 / main, Java 11+, Hawk token type enabled
(opt-in). (was: Apache CXF 3.5.7 / main, Java 11+, Hawk token type enabled
(opt-in).)
> Hawk validator: nonce/replay protection silently disabled by default
> (NonceVerifier never wired) — fail closed or auto-wire
> ---------------------------------------------------------------------------------------------------------------------------
>
> Key: CXF-9236
> URL: https://issues.apache.org/jira/browse/CXF-9236
> Project: CXF
> Issue Type: Improvement
> Components: JAX-RS Security
> Affects Versions: 3.6.10, 4.2.1
> Environment: Apache CXF 3.6.10 / main, Java 11+, Hawk token type
> enabled (opt-in).
> Reporter: Guanping Zhang
> Priority: Minor
>
> h3. Problem
> In AbstractHawkAccessTokenValidator, validateTimestampNonce(tokenKey, ts,
> nonce) is a no-op when nonceVerifier == null, which is the default (plain
> setter, no auto-construction). A grep of the entire tree shows no production
> code path that instantiates NonceVerifierImpl or wires it into a Hawk
> validator bean. Consequently, with the shipped default configuration, a
> captured Hawk Authorization header (id/ts/nonce/mac) replays verbatim for the
> token's lifetime: the MAC validates, but nothing enforces RFC 7669 §3.2 nonce
> single-use or timestamp freshness.
> Not at issue: the MAC comparison is constant-time (MessageDigest.isEqual) and
> token-type confusion is guarded; the gap is solely the silently-disabled
> replay protection.
> h3. Suggested improvement
> Either auto-wire a default NonceVerifierImpl in HawkAccessTokenValidator, or
> fail closed (reject) when no nonce verifier is configured for the Hawk
> scheme, so the validator cannot silently run with replay protection disabled.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)