Require TokenIssuer callers to pass explicit audiences

Summary

Split out of the Duo Workflow stateless-JWT work (work item #617039 (closed)). Authn::TokenExchange::TokenIssuer used to unconditionally append DATA_ACCESS_AUDIENCE to every minted token's aud claim, coupling every caller to it whether or not it needed it.

  • Renames the audience: keyword argument to audiences: (plural array) and drops the automatic append, so every caller must state exactly which audiences it wants, including DATA_ACCESS_AUDIENCE when it needs it.
  • audiences: must be non-empty; passing an empty array or nil raises ArgumentError. Duplicate audience values are deduplicated.
  • Adds optional scopes: and identities: kwargs, embedded as gitlab.scopes / gitlab.identities claims only when present.
  • Adds an optional routing: kwarg for top-level routing claims (c, o, u, p, g, t). The accepted keys are read from Authn::TokenField::Generator::RoutableToken::VALID_ROUTING_KEYS instead of a separate hand-maintained list, so the two allowlists can't drift apart.
  • Updates every existing caller to pass audiences explicitly: ee/lib/artifact_registry/token_exchange.rb, ee/lib/api/authn/token_exchange.rb (which always includes DATA_ACCESS_AUDIENCE, since every modular service using this endpoint needs Relationships/Lookup API access), and ee/app/services/authz/artifact_registry/base_service.rb.
  • Also updates Authz::Organizations::OwnerRoleSync#token_for, used by GrantOwnerRoleWorker/RevokeOwnerRoleWorker. This file landed on master after this MR's original merge base and still used the old audience: [] kwarg; left as-is it would have crashed both workers with ArgumentError: missing keyword: :audiences once merged. Rebased onto latest master to pick it up.

No behavior change for existing callers other than OwnerRoleSync -- the resulting aud claims are identical, just built explicitly instead of implicitly.

Related to Duo Workflow JWTs (#617039 - closed)

Test plan

  • ee/spec/lib/authn/token_exchange/token_issuer_spec.rb
  • ee/spec/lib/artifact_registry/token_exchange_spec.rb
  • ee/spec/requests/api/authn/token_exchange_spec.rb
  • ee/spec/services/authz/artifact_registry/{grant,revoke,lookup}_role_assignments_service_spec.rb
  • ee/spec/workers/authz/organizations/{grant,revoke}_owner_role_worker_spec.rb
Edited by Shilpa Kundapur

Merge request reports

Loading
Loading