[jira] [Commented] (JAMES-4195) JMAP - Allow configurable OIDC user identifier field

"Benoit Tellier (Jira)" <[email protected]> Thu, 18 Jun 2026 15:30:00 +0000 (UTC)
Newsgroups gmane.comp.jakarta.james.devel
Message-ID <[email protected]>
    [ https://issues.apache.org/jira/browse/JAMES-4195?page=3Dcom.atlassian=
.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=3D1808=
9948#comment-18089948 ]=20

Benoit Tellier commented on JAMES-4195:
---------------------------------------

Awesome, I'll schedule this with the team !

> JMAP - Allow configurable OIDC user identifier field
> ----------------------------------------------------
>
>                 Key: JAMES-4195
>                 URL: https://issues.apache.org/jira/browse/JAMES-4195
>             Project: James Server
>          Issue Type: Improvement
>          Components: JMAP
>            Reporter: Jean-Baptiste
>            Assignee: Antoine Duprat
>            Priority: Major
>
> *Current Context:* In the current implementation of {{JWTAuthenticationSt=
rategy}} (notably used by the *JMAP* endpoint), the user identity is strict=
ly extracted from the {{sub}} claim of the JSON Web Token. Additionally, th=
e public keys used for signature verification are typically loaded from loc=
al files or static configurations.
> *Problem 1: Hardcoded "sub" claim* In many modern Identity Providers (IdP=
) like Keycloak, Auth0, or Okta, the {{sub}} claim is an immutable internal=
 UUID (e.g., {{{}f:836c-22...{}}}). Apache James, however, requires a email=
 format username=C2=A0 (like {{{}[email protected]{}}}). Currently, there is =
no way to tell James to use another claim (e.g., {{{}preferred_username{}}}=
, {{{}email{}}}, or {{{}uid{}}}) as the source of truth for the user identi=
ty.
> *Problem 2: Static Public Key Management* Modern OIDC/OAuth2 architecture=
s use *JWKS (JSON Web Key Set)* endpoints to expose public keys. These keys=
 are subject to rotation for security reasons. Relying on a local static fi=
le for the public key makes rotation complex and prone to service interrupt=
ion.
> =C2=A0
> *Proposed Changes:*
>  # *Configurable Username Claim:* Introduce a configuration parameter to =
define which JWT claim should be mapped to the James Username.
>  # *JWKS Endpoint Support:* Allow James to fetch and cache public keys di=
rectly from a standard OIDC/JWKS URL instead of a local file.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)