yasithdev opened a new pull request, #688:
URL: https://github.com/apache/airavata/pull/688

   Makes gateway-admin authorization authoritative on the server. Previously 
the server trusted the bearer token without verifying its signature and 
enforced no coarse admin check, relying entirely on the portal flag.
   
   - **JWKS verification** (`JwtVerifier`): verifies the Keycloak access token 
(RS256 against the realm JWKS, `exp`, issuer) at the shared 
`AuthTokenExtractor` seam, with a per-issuer cached processor for multi-realm 
tenancy. Audience is intentionally not enforced (portal tokens carry 
`aud=account`). Verification is fail-closed but non-rejecting — an unverifiable 
token yields no roles (logged), so roles are only ever trusted from a 
signature-verified token and a forged token cannot assert admin.
   - **Roles in RequestContext**: `realm_access.roles` are written into the 
`AuthzToken` claims (server-derived, overwriting any client-asserted value) and 
surfaced as `RequestContext.isGatewayAdmin()` / `isReadOnlyGatewayAdmin()` 
(`admin-rw` / `admin-ro`).
   - **Enforcement** (`AdminAccess`): guards the gateway-wide admin operations 
— IAM user listing (`getUsers`), experiment statistics, and 
`getExperimentByAdmin` — requiring `admin-rw`/`admin-ro`. Per-entity sharing 
ACLs are unchanged.
   - **Bug fix**: `GrpcStatusMapper` only matched the exact class name 
`AuthorizationException`, so all 63 `ServiceAuthorizationException` throw sites 
mapped to `INTERNAL`; now mapped to `PERMISSION_DENIED`.
   
   Test plan (verified live): a `default-admin` (`admin-rw`) token still loads 
`/admin/users` (200) and experiment statistics (count 2); a valid non-admin 
(`user`-only) token gets `PERMISSION_DENIED`/403 on the admin ops; no 
JWT-verification warnings for portal traffic. Unit: `ExperimentServiceTest` 
(17) and `RequestContextTest` (2) pass.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to