Add option to require a valid aceess token audience #27567
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Add a config option to require OAuth2 access tokens to have an
audclaim.Previously, a
nullaudience was always added as a valid audience, meaning that an access token without theaudclaim would be accepted.This behaviour is not always desirable. This change introduces a new config option:
http-server.authentication.oauth2.require-audience=true/false.If
false(default), the behaviour is as before this change. Iftrue, access tokens without anaudclaim will not be accepted.Additional context and related issues
Similar issues have been raised before:
Release notes
( ) This is not user-visible or is docs only, and no release notes are required.
( ) Release notes are required. Please propose a release note for me.
(x) Release notes are required, with the following suggested text: