Loading
Add stateless JWT credentials for Duo Workflow
Summary
Part of work item #617039 (closed) and #617040 (closed). Duo Workflow needs short-lived credentials that don't require a DB row per token.
Authn::Tokens::StatelessAccessToken mints and verifies a prefixed (glsat-) RS256 JWT via TokenIssuer, duck-typing an OAuth access token via Authn::Tokens::Concerns::DoorkeeperCompatible so it plugs into the existing Doorkeeper/AccessTokenValidationService path.
StatelessAccessToken::Resultcarries the plaintext token back to the issuing caller;StatelessAccessToken::Denylistbacks revocation with a TTL-bounded Redis key, since there's no DB row to flag.- Composite-identity tokens (
gitlab.identitiesclaim) gate theduo_workflow_use_token_issuerflag on the embedded human user, and are rejected outright if that user can't be resolved (deleted account, or more than onekind:userentry) rather than silently falling back to gating on the service account. - Malformed payloads (missing
jti/exp/iat) are rejected inbuild_from_payloadrather than raising past theJWT::DecodeErrorrescue.
Gated behind the duo_workflow_use_token_issuer feature flag.
Depends on
- Targets !254059 (merged) (
Require TokenIssuer callers to pass explicit audiences) — needsTokenIssuer'saudiences:keyword. - Also depends on !254062 (merged) (
Extract Authn::Tokens::Concerns::DoorkeeperCompatible from IamOauthToken), merged into this branch directly so CI is green now. Once !254059 (merged) and !254062 (merged) land onmaster, this MR should be rebased to targetmasterdirectly — at that point its diff will shrink to just theStatelessAccessTokenfiles.
Test plan
-
ee/spec/lib/authn/tokens/stateless_access_token_spec.rb -
ee/spec/lib/authn/tokens/stateless_access_token/denylist_spec.rb
Edited by Shilpa Kundapur