]
Ilia Vassilev reassigned WFLY-7677:
-----------------------------------
Assignee: Ilia Vassilev (was: Darran Lofthouse)
Missing validation for write-attribute operation for
introspection-url from Elytron token-realm
-----------------------------------------------------------------------------------------------
Key: WFLY-7677
URL:
https://issues.jboss.org/browse/WFLY-7677
Project: WildFly
Issue Type: Bug
Components: Security
Affects Versions: 11.0.0.Alpha1
Reporter: Ondrej Lukas
Assignee: Ilia Vassilev
Labels: user_experience
{{add}} operation for Elytron {{token-realm}} checks whether
{{oauth2-introspection.introspection-url}} includes valid URL. However, in case when
invalid URL is added with write-attribute operation then there is no validation. It
results to failures during reloading/restarting server.