Validate token audience by default
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 85/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- authentication
Research direction
Start in src/auth/token-validator.ts, where the aud claim is only checked when tokenValidation.validateAudience is explicitly set to a truthy value. Update the default for this option to enable validation against the token's intended resourceUri, add an explicit opt-out configuration that emits a deprecation warning when used, and update related type definitions. Run the existing token validation test suite to verify the new default behavior and the opt-out path work as expected.
Written by the indexing model from the issue text.
Description
authorization.md (Token Validation) says servers MUST validate that access tokens were issued specifically for them as the intended audience, and MUST only accept tokens valid for their own resources.
src/auth/token-validator.ts checks aud only when tokenValidation.validateAudience is truthy, for both JWT and introspection, and the option defaults to undefined. With the default config, any token signed by a trusted issuer (or reported active by introspection) for a different resource server is accepted. That is the token-passthrough / confused-deputy case the spec warns about.
Proposal: validate aud against resourceUri by default, and keep an explicit opt-out for deployments that cannot (with a warning when it is used). This is a breaking change for setups whose tokens carry no audience, so it may need a major release or a deprecation period.
Related: #179 (issuer and claim checks). Found while reviewing #170. Already present on main.
- Dominant language
- TypeScript
- Stars
- 58
- Forks
- 13
- Avg merge
- 4h 50m
- Merged PRs (30d)
- 10
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from platformatic/mcp
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
platformatic/mcp#213 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
platformatic/mcp#207 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 25/100
platformatic/mcp#211 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 58/100
platformatic/mcp#210 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 58/100
platformatic/mcp#209 ·
Maintainers usually reply within 1 day
All issues in platformatic/mcp
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
kind/chore priority/must
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
sidereal-io/sidereal#380 ·
Maintainers usually reply within 1 day
-
Mend: dependency security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
opfab/operatorfabric-core#10653 ·
Maintainers usually reply within 1 day
-
backend bug size:sm
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
chrisbenincasa/tunarr#2237 ·
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 Half a day Newbie friendliness 69/100
Lam30ne/regulate-app#39 ·