yasithdev opened a new pull request, #695: URL: https://github.com/apache/airavata/pull/695
Authenticates every client from the verified Keycloak access token alone, so a Keycloak token is sufficient to call the API directly. Closes a gap where caller identity was trusted from client-supplied `x-claims` headers and invalid/expired tokens were accepted. **Server (`airavata-server`)** - `JwtVerifier.verify()` returns a `VerifiedToken` (userName from `preferred_username`, gatewayId from the issuer realm, realm roles) and throws on a missing, malformed, expired, or unverifiable token. - `GrpcAuthInterceptor` and `HttpAuthDecorator` reject such requests (`UNAUTHENTICATED` / `401`); `x-claims` / `x-user-name` / `x-gateway-id` are no longer read. - `AuthTokenExtractor` builds the `AuthzToken` claims map from the verified token only. `UserContext` and its readers are unchanged. - Adds `JwtVerifierTest` (pure identity-derivation unit tests). **SDK (`airavata-python-sdk`)** — sends only the Keycloak access token (Bearer) across the facade, all service clients, the transport layer, and the experiment/Jupyter helpers; no `x-claims`. **Keycloak** — adds the public `pga-public` client (Authorization Code + PKCE) for browser clients. **Build** — the Tilt build step runs `mvn clean install` to avoid stale generated sources. ### Test plan - `mvn test -pl airavata-server -Dtest=JwtVerifierTest` — green. - Live: a raw Keycloak token (no `x-claims`) returns the user's data; garbage / tampered / expired tokens return `401`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
