Mint and revoke stateless JWTs in Duo Workflow services

What does this MR do and why?

Route Duo Workflow credential issuance and revocation through the stateless JWTs added in the substrate MR, when the default-off duo_workflow_use_token_issuer flag is enabled. Falls back to the existing Doorkeeper OAuth path otherwise.

Five services in ee/app/services/ai/duo_workflows/ and ee/app/services/ai/flow_triggers/:

  • CreateOauthAccessTokenService and CreateCompositeOauthAccessTokenService — issue a StatelessAccessToken JWT instead of an OauthAccessToken row. For the composite case, the human user goes into the JWT's identities claim rather than a user:<id> OAuth scope.
  • RevokeTokenService — revokes a StatelessAccessToken JWT via the Redis denylist, keeping the Doorkeeper revocation path for OAuth tokens.
  • WorkflowContextGenerationService — reads composite identity from the JWT's identities claim when the token is a StatelessAccessToken.
  • FlowTriggers::RunService — allows composite identity without a Doorkeeper OAuth application configured, when the flag is enabled.

This is one of two MRs split out from the original 1000+ line MR so each piece reviews independently. It depends on the substrate MR (StatelessAccessToken.issue/.enabled?/.from_jwt) but not on the sibling auth-wiring MR — they can review and merge in parallel.

References

Screenshots or screen recordings

Not applicable — backend-only change, no UI.

How to set up and validate locally

  1. Ensure !253247 (closed) (the substrate MR) is present on this branch.
  2. Enable the feature flag for a test user: Feature.enable(:duo_workflow_use_token_issuer, User.find_by(username: 'your_username')).
  3. Trigger a Duo Workflow run for that user; it now receives a glsat--prefixed JWT instead of a Doorkeeper OAuth token.
  4. Run the updated specs:
    bundle exec rspec ee/spec/services/ai/duo_workflows/ ee/spec/services/ai/flow_triggers/run_service_spec.rb
  5. Full end-to-end validation of the JWT actually authenticating a request needs the sibling auth-wiring MR too.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Shilpa Kundapur

Merge request reports

Loading
Loading