yasithdev opened a new pull request, #688: URL: https://github.com/apache/airavata/pull/688
Makes gateway-admin authorization authoritative on the server. Previously the server trusted the bearer token without verifying its signature and enforced no coarse admin check, relying entirely on the portal flag. - **JWKS verification** (`JwtVerifier`): verifies the Keycloak access token (RS256 against the realm JWKS, `exp`, issuer) at the shared `AuthTokenExtractor` seam, with a per-issuer cached processor for multi-realm tenancy. Audience is intentionally not enforced (portal tokens carry `aud=account`). Verification is fail-closed but non-rejecting — an unverifiable token yields no roles (logged), so roles are only ever trusted from a signature-verified token and a forged token cannot assert admin. - **Roles in RequestContext**: `realm_access.roles` are written into the `AuthzToken` claims (server-derived, overwriting any client-asserted value) and surfaced as `RequestContext.isGatewayAdmin()` / `isReadOnlyGatewayAdmin()` (`admin-rw` / `admin-ro`). - **Enforcement** (`AdminAccess`): guards the gateway-wide admin operations — IAM user listing (`getUsers`), experiment statistics, and `getExperimentByAdmin` — requiring `admin-rw`/`admin-ro`. Per-entity sharing ACLs are unchanged. - **Bug fix**: `GrpcStatusMapper` only matched the exact class name `AuthorizationException`, so all 63 `ServiceAuthorizationException` throw sites mapped to `INTERNAL`; now mapped to `PERMISSION_DENIED`. Test plan (verified live): a `default-admin` (`admin-rw`) token still loads `/admin/users` (200) and experiment statistics (count 2); a valid non-admin (`user`-only) token gets `PERMISSION_DENIED`/403 on the admin ops; no JWT-verification warnings for portal traffic. Unit: `ExperimentServiceTest` (17) and `RequestContextTest` (2) pass. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
