Loading
Require TokenIssuer callers to pass explicit audiences
Summary
Split out of the Duo Workflow stateless-JWT work (work item #617039 (closed)). Authn::TokenExchange::TokenIssuer used to unconditionally append DATA_ACCESS_AUDIENCE to every minted token's aud claim, coupling every caller to it whether or not it needed it.
- Renames the
audience:keyword argument toaudiences:(plural array) and drops the automatic append, so every caller must state exactly which audiences it wants, includingDATA_ACCESS_AUDIENCEwhen it needs it. audiences:must be non-empty; passing an empty array ornilraisesArgumentError. Duplicate audience values are deduplicated.- Adds optional
scopes:andidentities:kwargs, embedded asgitlab.scopes/gitlab.identitiesclaims only when present. - Adds an optional
routing:kwarg for top-level routing claims (c,o,u,p,g,t). The accepted keys are read fromAuthn::TokenField::Generator::RoutableToken::VALID_ROUTING_KEYSinstead of a separate hand-maintained list, so the two allowlists can't drift apart. - Updates every existing caller to pass audiences explicitly:
ee/lib/artifact_registry/token_exchange.rb,ee/lib/api/authn/token_exchange.rb(which always includesDATA_ACCESS_AUDIENCE, since every modular service using this endpoint needs Relationships/Lookup API access), andee/app/services/authz/artifact_registry/base_service.rb. - Also updates
Authz::Organizations::OwnerRoleSync#token_for, used byGrantOwnerRoleWorker/RevokeOwnerRoleWorker. This file landed on master after this MR's original merge base and still used the oldaudience: []kwarg; left as-is it would have crashed both workers withArgumentError: missing keyword: :audiencesonce merged. Rebased onto latest master to pick it up.
No behavior change for existing callers other than OwnerRoleSync -- the resulting aud claims are identical, just built explicitly instead of implicitly.
Related to Duo Workflow JWTs (#617039 - closed)
Test plan
-
ee/spec/lib/authn/token_exchange/token_issuer_spec.rb -
ee/spec/lib/artifact_registry/token_exchange_spec.rb -
ee/spec/requests/api/authn/token_exchange_spec.rb -
ee/spec/services/authz/artifact_registry/{grant,revoke,lookup}_role_assignments_service_spec.rb -
ee/spec/workers/authz/organizations/{grant,revoke}_owner_role_worker_spec.rb
Edited by Shilpa Kundapur