Failed to validate dpop error #3209
|
Hello, Due to org network blocking, i had to deploy entire platform with port 443. but java code using the SDK does not. it gives error Current Configuration OpenTDF config (opentdf.yaml) Any clue/flag i need to set in code ? |
Replies: 1 comment 1 reply
|
Hi @mm192010 , thanks for the detailed write-up — the configuration context is really helpful. We dug into this and what's happening is the Java SDK sets the DPoP
The server does have We've filed #3216 to track fixes needed on both the server and SDK sides. In the meantime, if you need an immediate workaround: if your Keycloak is not issuing tokens with the Thanks again for surfacing this — it's helping us close a real gap in our DPoP support for reverse-proxy deployments. |
Hi @mm192010 , thanks for the detailed write-up — the configuration context is really helpful.
We dug into this and what's happening is the Java SDK sets the DPoP
htuclaim to the full URL per RFC 9449 — e.g.,https://platform.opentdf.company.com/policy.namespaces.NamespaceService/GetNamespace. But on the server side, the ConnectRPC interceptor only has the bare procedure path (/policy.namespaces.NamespaceService/GetNamespace) in its allowedhtulist, so the match fails.otdfctlis working because the Go SDK and the server currently agree on using just the procedure path ashtu, so the match succeeds. The Java SDK includes the full origin, which the server isn't yet set up to accept in th…