Loading...
Loading...
Invalid 'sub' claim in JWT access token that is generated by OAuth Authorization Server.
Invalid value in 'sub' claim in JWT access token. If OAuth resource server depends on the value of 'sub' claim, then that functionality does not work.
-- OAuth Authorization Server is configured to return JWT access token. -- Subject field is configured to be a session variable other than the default '%{session.assigned.uuid}'.
Add Variable assign agent after OAuth Authorization agent, and assign session.assigned.oauth.authz.token.subject with the session variable name such as the following: session.logon.last.logonname.
OAuth Authorization Server sends valid value in 'sub' claim in the generated JWT token when subject is configured to use a session variable.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.