Skip to content

Forbid requests whose token has no subject claim, instead of failing with 500 - #5984

Draft
ramonsmits wants to merge 1 commit into
masterfrom
fix-missing-subject-claim-forbidden
Draft

ramonsmits wants to merge 1 commit into
masterfrom
fix-missing-subject-claim-forbidden

Conversation

@ramonsmits

Copy link
Copy Markdown
Member

With role-based authorization enabled, a token without the subject ID claim (sub) or the subject name claim (preferred_username) gets 500 Internal Server Error on every API request. The authorization handler throws because the audit log needs both values. The handler now denies the request with 403 Forbidden, and logs a warning that names the missing claim and the setting that configures it.

  • PermissionVerbHandler fails the requirement and logs a warning, instead of throwing.
  • Remove ClaimsPrinicpalExtensionMethods.RequireClaim. The handler was its only caller.
  • New tests: an admin token without sub or preferred_username is denied every permission.

…g with 500

With role-based authorization enabled, PermissionVerbHandler needs the
subject ID and subject name claims for the authorization audit log. When a
token did not have one of them, the handler threw an
InvalidOperationException, and every request with that token got 500.

The handler now denies the request (403) and logs a warning that names
the missing claim and the setting that configures it.

- Remove ClaimsPrinicpalExtensionMethods.RequireClaim. The handler was its
  only caller.
- New tests: an admin token without sub or preferred_username is denied
  every permission.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants