rjgoyln opened a new pull request, #70825:
URL: https://github.com/apache/airflow/pull/70825

    ## Summary
   This PR enhances the Authentik OAuth provider's security by enforcing JWT 
claim validation (`aud` and `iss`). A valid signature only proves the token 
originated from the identity provider, so this change strictly pins the 
audience to prevent cross-client token abuse (e.g., using a valid token issued 
to another application on the same IdP to log into Airflow).
   
   ## Changes
   * **Enhanced JWT Validation:** Updated `_validate_jwt` to accept and pass 
`claims_options` to `authlib_jwt.decode()` for strict claim verification.
   * **Mandatory Audience Check:** Implemented 
`_get_authentik_claims_options()` to enforce that the `aud` (audience) claim 
strictly matches the configured `client_id`.
   * **Flexible Issuer Check:** Added conditional validation for the `iss` 
(issuer) claim. If `issuer` is not defined in `server_metadata`, it logs a 
warning rather than failing, avoiding a breaking change for existing 
deployments.
   * **Comprehensive Testing:** Added regression tests 
(`TestAuthentikIdTokenClaimValidation`) utilizing real RSA keypairs to 
thoroughly verify happy paths, missing claims, and invalid claim rejections.
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   - [X] Yes (please specify the tool below)
   Drafted-by: Claude Code (Opus 5)
   
   ---
   
   * Read the **[Pull Request 
Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)**
 for more information. Note: commit author/co-author name and email in commits 
become permanently public when merged.
   * For fundamental code changes, an Airflow Improvement Proposal 
([AIP](https://cwiki.apache.org/confluence/display/AIRFLOW/Airflow+Improvement+Proposals))
 is needed.
   * When adding dependency, check compliance with the [ASF 3rd Party License 
Policy](https://www.apache.org/legal/resolved.html#category-x).
   * For significant user-facing changes create newsfragment: 
`{pr_number}.significant.rst`, in 
[airflow-core/newsfragments](https://github.com/apache/airflow/tree/main/airflow-core/newsfragments).
 You can add this file in a follow-up commit after the PR is created so you 
know the PR number.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to