CAMEL-25022: camel-oauth - honor the JWT nbf claim when authenticating bearer tokens on the servlet backend - #26893
Conversation
…g bearer tokens on the servlet backend UserProfile.verifyToken() now rejects a token whose nbf (not before) claim is later than the current time plus the JWTOptions leeway (default 0), as RFC 7519 section 4.1.5 requires. The servlet backend previously evaluated only exp; the Vert.x backend and the OAuthTokenValidationFactory SPI already evaluate nbf. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
|
🌟 Thank you for your contribution to the Apache Camel project! 🌟 🐫 Apache Camel Committers, please review the following items:
|
gnodet-bot
left a comment
There was a problem hiding this comment.
Solid fix. The nbf check is RFC 7519 §4.1.5 compliant, correctly applies the configured leeway, and is properly guarded against absent claims. The existing expired() / exp asymmetry (no leeway on staleness check) is pre-existing and out of scope. Tests cover rejection, acceptance, and leeway boundary — adequate. Upgrade guide is accurate.
Milestone should be set to 4.23.0.
This review was generated by an AI agent, Hermès on behalf of @gnodet.
|
🧪 CI tested the following changed modules:
🔬 Scalpel shadow comparison — Scalpel: 9 of 695 tested, 26 compile-only — current: 9 all testedMaveniverse Scalpel detected 9 affected modules (current approach: 9). Skip-tests mode would test 9 modules (2 direct + 8 downstream), skip tests for 26 (generated code, meta-modules) Modules Scalpel would test (9)
Modules with tests skipped (26)
All tested modules (36 modules, 5m 32s total)Total reactor time: 5m 32s
Top 20 slowest modules:
|
davsclaus
left a comment
There was a problem hiding this comment.
Thanks @oscerd — a correct, well-tested fix that brings the servlet backend in line with Vert.x and the SPI validator.
A small doc point: the upgrade note refers to the leeway on JWTOptions, but on the servlet backend ServletOAuth builds the OAuthConfig from camel.oauth.* properties and nothing sets the leeway. It can only be changed from code (oauth.getOAuthConfig().getJWTOptions().setLeeway(n)), and clock-skew-seconds applies only to the SPI validator. Some identity providers issue nbf == iat, so a provider clock running slightly ahead would now reject fresh tokens with the default of 0. Could the note say how to set it (or should a follow-up expose a property)?
Nit: this adds a fourth === camel-oauth heading right after the existing one. Merging it into that section, or giving it a specific title, would read better.
This review was generated by an AI agent on behalf of davsclaus and may contain inaccuracies. Please verify all suggestions before applying.
…e servlet backend ServletOAuth.discoverOAuthConfig only sets the issuer on JWTOptions, so the leeway stays at 0 and clock-skew-seconds does not reach it. Show how to set it on the OAuth instance for identity providers whose clock runs ahead. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
gnodet-bot
left a comment
There was a problem hiding this comment.
Re-review after 8eade5a. @davsclaus asked how users can raise the nbf leeway on the servlet backend — addressed: the upgrade guide now explains that clock-skew-seconds does not feed UserProfile, and shows the getJWTOptions().setLeeway(n) call.
Minor: this adds a fourth === camel-oauth heading in the upgrade guide (line 1847) right after the existing one (line 1824). Merging into the existing section would read better, but it's cosmetic and doesn't block.
This review was generated by an AI agent, Hermès on behalf of @gnodet.
What
When
OAuthBearerTokenProcessorauthenticates an access token through the Jakarta servlet backend(
ServletOAuth),UserProfilevalidated the JWS signature and the issuer, andUserProfile.expired()evaluated
exp, but thenbf(not before) claim was only copied into the profile attributes and neverevaluated. RFC 7519 section 4.1.5 specifies that a JWT must not be accepted for processing before its
nbftime. The Vert.x backend (through Vert.x
User.expired(leeway)) and theOAuthTokenValidationFactorySPI(
JwtTokenValidator) already evaluatenbf.Changes
UserProfile.verifyToken()— reject a token whosenbfis later than the current time plus the leewayconfigured in
JWTOptions(getLeeway(), default0, the same default as the Vert.x backend and the SPIclock-skew-secondsoption). Tokens without annbfclaim are unaffected.leeway from configuration (
clock-skew-secondsfeeds only the SPI), and shows how to raise it on theOAuthinstance for identity providers whose clock runs ahead and which issuenbf == iat.Tests
UserProfileTest— a token with a futurenbfis rejected, a token whosenbfhas passed is accepted,and the configured leeway is honored (accepted within it, rejected beyond it).
ServletOAuthTokenCredentialsTest(new) — the servlet bearer path,ServletOAuth.authenticate(TokenCredentials),rejects a token before its
nbfand accepts it afterwards, without contacting an identity provider.mvn clean installincomponents/camel-oauth: 141 tests, 0 failures (the 7 skipped are the existingKeycloak-environment tests). Full reactor
mvn clean install -DskipTests -DskipITs: green.The backports to
camel-4.22.xandcamel-4.18.xwill follow once this is merged, together with the matching4.22 / 4.18 upgrade-guide notes on main.
JIRA: https://issues.apache.org/jira/browse/CAMEL-25022
Claude Code on behalf of oscerd
🤖 Generated with Claude Code