Add cell_id to IAM login accept and fix Workhorse token prefixes
This MR adds cell_id routing support to gitlab-rails' IAM OAuth integration and fixes incorrect token-prefix matching in Workhorse's OAuth proxy. IAM now stamps both user ID (u) and cell ID (c) claims onto OAuth tokens for the Cells HTTP Router to read. gitlab-rails must send the cell ID when accepting login challenges so IAM can include it in the issued token.
What does this MR do and why?
Routable tokens (#604548 - closed)
OAuth tokens issued by IAM need to carry both user ID and cell ID claims for the Cells HTTP Router to route requests to the correct cell. This MR enables that flow in three commits:
-
Update IAM gRPC Client Gem to 6119be5: Regenerates the vendored
vendor/gems/gitlab-iam-grpcgem from IAM's604548-oauth-access-token-cell-claimbranch (MR gitlab-org/auth/iam!590 (merged), stacked on !588 (merged)). Addscell_id(int64) toLoginServiceAcceptRequestin the proto contract using the existingscripts/update-iam-grpc-client.shscript. -
Send cell_id on IAM login challenge accept calls: Updates
app/services/authn/iam_service/accept_login_challenge_service.rbto sendcell_id: Gitlab.config.cell.id.to_ion eachaccept_login_challengecall. The Cells HTTP Router routes every request to its owning cell before Rails runs, so the localGitlab.config.cell.idvalue is correct — no per-request Topology Service lookup is needed. This matches existing patterns inlib/ci/job_token/jwt.rbandlib/authn/token_field/generator/routable_token.rb. -
Fix stale IAM token prefixes in Workhorse OAuth routing: Corrects
workhorse/internal/oauthproxy/oauthproxy.gotoken-prefix matching. Old prefixesgiat_andory_were never correct:giat_was a placeholder that never shipped,ory_is fosite's default which IAM replaces before tokens leave its service. Real prefixes aregliamac-(authorize code),gliamat-(access token),gliamrt-(refresh token), verified againstgitlab-org/auth/iam'sauth/oauth/core/token_prefix.go.
References
gitlab-org/auth/iam!590 (merged) https://handbook.gitlab.com/handbook/engineering/architecture/design-documents/cells/routable_tokens/
How to set up and validate locally
Tests for the Rails changes pass: spec/services/authn/iam_service/accept_login_challenge_service_spec.rb and spec/lib/authn/iam_service/grpc_client_spec.rb. Workhorse tests pass: go test ./internal/oauthproxy/.... Rubocop and gofmt/go vet pass without issues. End-to-end validation (building IAM locally, running a real OAuth login through GDK, decoding tokens) is in progress separately.