box / box/box-java-sdk

Make IPrivateKeyDecryptor Instantiation Configurable in JWTEncryptionPreferences to avoid compilation-time errors

未关闭
#1,310 1 条评论 0 个 reaction 已指派 5 人 已被 @mwwoda 认领 在 GitHub 查看
enhancement
主要语言
Java
星标
170
派生
189
平均合并
20 小时 26 分钟
30 天内合并 PR
22

描述

### Is your feature request related to a problem? Please describe.
The class `JWTEncryptionPreferences` has a private `IPrivateKeyDecryptor` field (`privateKeyDecryptor`) that is instantiated immediately with `BCPrivateKeyDecryptor()`. Although it is possible to override the `IPrivateKeyDecryptor` later via a call to `boxConfig.setPrivateKeyDecryptor`, by the time this becomes possible, `BCPrivateKeyDecryptor()` has already been instantiated. `BCPrivateKeyDecryptor` imports `BouncyCastleProvider`, which we exclude from dependencies to ensure that only FIPS-compliant BouncyCastle libraries are present, resulting in a failure.

### Describe the solution you'd like
It would be helpful if the instantiation of `JWTEncryptionPreferences` became more configurable. For example, moving this instantiation to a default constructor while allowing an alternative constructor, or utilizing interfaces to make it easier to override the functionality altogether.

### Describe alternatives you've considered
1. Allowing `BouncyCastleProvider` in just for the sake of not receiving compilation-time errors.
2. Implementing a fake `BouncyCastleProvider` to "trick" the compiler.
3. Using reflection.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。