rjgoyln opened a new pull request, #70825:
URL: https://github.com/apache/airflow/pull/70825
## Summary
This PR enhances the Authentik OAuth provider's security by enforcing JWT
claim validation (`aud` and `iss`). A valid signature only proves the token
originated from the identity provider, so this change strictly pins the
audience to prevent cross-client token abuse (e.g., using a valid token issued
to another application on the same IdP to log into Airflow).
## Changes
* **Enhanced JWT Validation:** Updated `_validate_jwt` to accept and pass
`claims_options` to `authlib_jwt.decode()` for strict claim verification.
* **Mandatory Audience Check:** Implemented
`_get_authentik_claims_options()` to enforce that the `aud` (audience) claim
strictly matches the configured `client_id`.
* **Flexible Issuer Check:** Added conditional validation for the `iss`
(issuer) claim. If `issuer` is not defined in `server_metadata`, it logs a
warning rather than failing, avoiding a breaking change for existing
deployments.
* **Comprehensive Testing:** Added regression tests
(`TestAuthentikIdTokenClaimValidation`) utilizing real RSA keypairs to
thoroughly verify happy paths, missing claims, and invalid claim rejections.
---
##### Was generative AI tooling used to co-author this PR?
- [X] Yes (please specify the tool below)
Drafted-by: Claude Code (Opus 5)
---
* Read the **[Pull Request
Guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#pull-request-guidelines)**
for more information. Note: commit author/co-author name and email in commits
become permanently public when merged.
* For fundamental code changes, an Airflow Improvement Proposal
([AIP](https://cwiki.apache.org/confluence/display/AIRFLOW/Airflow+Improvement+Proposals))
is needed.
* When adding dependency, check compliance with the [ASF 3rd Party License
Policy](https://www.apache.org/legal/resolved.html#category-x).
* For significant user-facing changes create newsfragment:
`{pr_number}.significant.rst`, in
[airflow-core/newsfragments](https://github.com/apache/airflow/tree/main/airflow-core/newsfragments).
You can add this file in a follow-up commit after the PR is created so you
know the PR number.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]