Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-6338

Reversed logic in AbstractJwtHandler#validateSignature

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 3.0.4
    • 3.1, 3.0.5
    • JAX-RS Security
    • None
    • Unknown

    Description

      The logic in the validateSignature method in org.apache.cxf.rs.security.oauth2.grants.jwt.AbstractJwtHandler is reversed - the method throws an OAuthServiceException when the signature is valid and doesn't throw an exception when the signature is not valid.

      Attachments

        Activity

          People

            sergey_beryozkin Sergey Beryozkin
            jsamarziya Jeffrey Samarziya
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: