Mint and revoke stateless JWTs in Duo Workflow services
What does this MR do and why?
Route Duo Workflow credential issuance and revocation through the stateless JWTs added in the substrate MR, when the default-off duo_workflow_use_token_issuer flag is enabled. Falls back to the existing Doorkeeper OAuth path otherwise.
Five services in ee/app/services/ai/duo_workflows/ and ee/app/services/ai/flow_triggers/:
CreateOauthAccessTokenServiceandCreateCompositeOauthAccessTokenService— issue aStatelessAccessTokenJWT instead of anOauthAccessTokenrow. For the composite case, the human user goes into the JWT'sidentitiesclaim rather than auser:<id>OAuth scope.RevokeTokenService— revokes aStatelessAccessTokenJWT via the Redis denylist, keeping the Doorkeeper revocation path for OAuth tokens.WorkflowContextGenerationService— reads composite identity from the JWT'sidentitiesclaim when the token is aStatelessAccessToken.FlowTriggers::RunService— allows composite identity without a Doorkeeper OAuth application configured, when the flag is enabled.
This is one of two MRs split out from the original 1000+ line MR so each piece reviews independently. It depends on the substrate MR (StatelessAccessToken.issue/.enabled?/.from_jwt) but not on the sibling auth-wiring MR — they can review and merge in parallel.
References
- Related to #617069
- Depends on !253247 (closed) (substrate)
Screenshots or screen recordings
Not applicable — backend-only change, no UI.
How to set up and validate locally
- Ensure !253247 (closed) (the substrate MR) is present on this branch.
- Enable the feature flag for a test user:
Feature.enable(:duo_workflow_use_token_issuer, User.find_by(username: 'your_username')). - Trigger a Duo Workflow run for that user; it now receives a
glsat--prefixed JWT instead of a Doorkeeper OAuth token. - Run the updated specs:
bundle exec rspec ee/spec/services/ai/duo_workflows/ ee/spec/services/ai/flow_triggers/run_service_spec.rb - Full end-to-end validation of the JWT actually authenticating a request needs the sibling auth-wiring MR too.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.