Skip to content

Commit bf66072

Browse files
committed
Add check for requested token type
1 parent 5cc5c1e commit bf66072

File tree

1 file changed

+3
-0
lines changed
  • service/common/src/main/java/org/apache/polaris/service/auth

1 file changed

+3
-0
lines changed

service/common/src/main/java/org/apache/polaris/service/auth/JWTBroker.java

+3
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,9 @@ public TokenResponse generateFromToken(
103103
String grantType,
104104
String scope,
105105
TokenType requestedTokenType) {
106+
if (!TokenType.ACCESS_TOKEN.equals(requestedTokenType)) {
107+
return new TokenResponse(OAuthTokenErrorResponse.Error.invalid_request);
108+
}
106109
if (!TokenType.ACCESS_TOKEN.equals(subjectTokenType)) {
107110
return new TokenResponse(OAuthTokenErrorResponse.Error.invalid_request);
108111
}

0 commit comments

Comments
 (0)