Add cell_id to IAM login accept and fix Workhorse token prefixes

This MR adds cell_id routing support to gitlab-rails' IAM OAuth integration and fixes incorrect token-prefix matching in Workhorse's OAuth proxy. IAM now stamps both user ID (u) and cell ID (c) claims onto OAuth tokens for the Cells HTTP Router to read. gitlab-rails must send the cell ID when accepting login challenges so IAM can include it in the issued token.

What does this MR do and why?

Routable tokens (#604548 - closed)

OAuth tokens issued by IAM need to carry both user ID and cell ID claims for the Cells HTTP Router to route requests to the correct cell. This MR enables that flow in three commits:

  • Update IAM gRPC Client Gem to 6119be5: Regenerates the vendored vendor/gems/gitlab-iam-grpc gem from IAM's 604548-oauth-access-token-cell-claim branch (MR gitlab-org/auth/iam!590 (merged), stacked on !588 (merged)). Adds cell_id (int64) to LoginServiceAcceptRequest in the proto contract using the existing scripts/update-iam-grpc-client.sh script.

  • Send cell_id on IAM login challenge accept calls: Updates app/services/authn/iam_service/accept_login_challenge_service.rb to send cell_id: Gitlab.config.cell.id.to_i on each accept_login_challenge call. The Cells HTTP Router routes every request to its owning cell before Rails runs, so the local Gitlab.config.cell.id value is correct — no per-request Topology Service lookup is needed. This matches existing patterns in lib/ci/job_token/jwt.rb and lib/authn/token_field/generator/routable_token.rb.

  • Fix stale IAM token prefixes in Workhorse OAuth routing: Corrects workhorse/internal/oauthproxy/oauthproxy.go token-prefix matching. Old prefixes giat_ and ory_ were never correct: giat_ was a placeholder that never shipped, ory_ is fosite's default which IAM replaces before tokens leave its service. Real prefixes are gliamac- (authorize code), gliamat- (access token), gliamrt- (refresh token), verified against gitlab-org/auth/iam's auth/oauth/core/token_prefix.go.

References

gitlab-org/auth/iam!590 (merged) https://handbook.gitlab.com/handbook/engineering/architecture/design-documents/cells/routable_tokens/

How to set up and validate locally

Tests for the Rails changes pass: spec/services/authn/iam_service/accept_login_challenge_service_spec.rb and spec/lib/authn/iam_service/grpc_client_spec.rb. Workhorse tests pass: go test ./internal/oauthproxy/.... Rubocop and gofmt/go vet pass without issues. End-to-end validation (building IAM locally, running a real OAuth login through GDK, decoding tokens) is in progress separately.

Edited by Shilpa Kundapur

Merge request reports

Loading
Loading