davsclaus opened a new pull request, #27601:
URL: https://github.com/apache/camel/pull/27601

   ## Summary
   
   Fixes [CAMEL-25486](https://issues.apache.org/jira/browse/CAMEL-25486).
   
   With the `oauth2ResourceIndicator` option (RFC 8707, added in CAMEL-21712), 
the OAuth2 client credentials token request only contained the `resource` 
parameter. The body was built like this:
   
   ```java
   bodyStr = String.join(bodyStr, "&resource=" + resourceIndicator);
   ```
   
   `String.join(delimiter, elements...)` with a single element returns just 
that element, so the body became `&resource=<value>`. That dropped 
`grant_type`, `scope`, and the `client_id`/`client_secret` sent with 
`oauth2BodyAuthentication`. A token endpoint rejects such a request, so the 
option didn't work at all.
   
   ## Changes
   - `OAuth2ClientConfigurer`: append the `resource` parameter to the body 
instead.
   - New `HttpOAuth2ResourceIndicatorTest`: the token endpoint records the 
token request, and the test checks `grant_type`, `scope`, `resource` and, with 
body authentication, `client_id` and `client_secret`. Both tests fail without 
the fix: `grant_type` is `null`.
   
   No docs or upgrade-guide change: the option now works as documented.
   
   Found while reviewing #27589.
   
   ## Tests
   - camel-http: all tests pass (264), including the 2 new ones.
   
   _Claude Code on behalf of davsclaus_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to