Uploaded image for project: 'WildFly'
  1. WildFly
  2. WFLY-14095

Updates to the SmallRye JWT integration to remove requirement for EE Security

    XMLWordPrintable

Details

    • Enhancement
    • Resolution: Unresolved
    • Major
    • None
    • 22.0.0.Alpha1
    • MP JWT, Security
    • None
    • Undefined
    • ---
    • ---

    Description

      At the moment activation of MP-JWT triggers the activation of EE Security and JASPIC, at it's core the MP-JWT specification is a simple header based authentication mechanism so we should be able to cut out the additional layers.

      The main requirement will still be that the microprofile-jwt subsystem performs the same actions to detect the need to activate MP-JWT. 

      The subsystem can likely make a HttpAuthenticationFactory available for use later.

      A key point here is the mechanism will still need to be coming from the application for the relevant CDI integration.

       

      Attachments

        Activity

          People

            Unassigned Unassigned
            darran.lofthouse@redhat.com Darran Lofthouse
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: