Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-5764

AccessTokenService should allow the client authentication with a client id only

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • None
    • 3.0.1
    • JAX-RS Security
    • None
    • Unknown

    Description

      In some cases we may have a client_id parameter available, but no client_secret, the latter may be encrypted in client_id or some other parameter such as an assertion may securely identify a client.
      At the moment if AccessTokenService sees a client_id parameter it will enforce the presence of client_secret for the confidential clients which may block the valid clients.

      Attachments

        Activity

          People

            sergey_beryozkin Sergey Beryozkin
            sergey_beryozkin Sergey Beryozkin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: