Skip to content
Discussion options

You must be logged in to vote

Hi @mm192010 , thanks for the detailed write-up — the configuration context is really helpful.

We dug into this and what's happening is the Java SDK sets the DPoP htu claim to the full URL per RFC 9449 — e.g., https://platform.opentdf.company.com/policy.namespaces.NamespaceService/GetNamespace. But on the server side, the ConnectRPC interceptor only has the bare procedure path (/policy.namespaces.NamespaceService/GetNamespace) in its allowed htu list, so the match fails.

otdfctl is working because the Go SDK and the server currently agree on using just the procedure path as htu, so the match succeeds. The Java SDK includes the full origin, which the server isn't yet set up to accept in th…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ttschampel
Comment options

Answer selected by jrschumacher
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants