Add stateless JWT infrastructure for Duo Workflow credentials

What does this MR do and why?

Introduce substrate for issuing and verifying short-lived RS256 JWTs as an interim credential format for Duo Workflow, before OAuth issuance moves to the IAM service.

Three new classes in ee/lib/authn/tokens/ and ee/lib/authn/token_exchange/:

  • TokenExchange::TokenIssuer — extends token issuance with a gitlab-rails audience and claims for scopes, identities, and routing.
  • StatelessAccessToken — verifies JWTs and duck-types the OAuth token interface (scopes, resource_owner_id, accessible?, application, scope_user).
  • StatelessAccessTokenDenylist — short-lived Redis-backed revocation, since no DB row exists for these tokens.
  • StatelessAccessTokenResult — plain struct wrapping the issued token's fields.

All gated by the duo_workflow_use_token_issuer feature flag (default off). This MR is pure substrate: no auth acceptance and no Duo Workflow issuance changes yet, so there is no runtime behavior change on its own. It's verified by its own specs.

This MR was split out of the original, larger version of this MR (1000+ lines) so each piece can be reviewed independently. Two follow-up MRs build on this one and can review/merge in parallel with each other:

  • !253732 (merged) — auth acceptance (git-over-HTTPS, API bearer token) for these JWTs.
  • !253733 (merged) — Duo Workflow issuance and revocation of these JWTs.

References

Screenshots or screen recordings

Not applicable — backend-only change, no UI.

How to set up and validate locally

  1. Run the new specs:
    bundle exec rspec ee/spec/lib/authn/tokens/ ee/spec/lib/authn/token_exchange/token_issuer_spec.rb
  2. Nothing calls this code yet outside specs — no other manual validation is possible until the follow-up MRs land.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Shilpa Kundapur

Merge request reports

Loading
Loading