yasithdev opened a new pull request, #695:
URL: https://github.com/apache/airavata/pull/695

   Authenticates every client from the verified Keycloak access token alone, so 
a Keycloak token is sufficient to call the API directly. Closes a gap where 
caller identity was trusted from client-supplied `x-claims` headers and 
invalid/expired tokens were accepted.
   
   **Server (`airavata-server`)**
   - `JwtVerifier.verify()` returns a `VerifiedToken` (userName from 
`preferred_username`, gatewayId from the issuer realm, realm roles) and throws 
on a missing, malformed, expired, or unverifiable token.
   - `GrpcAuthInterceptor` and `HttpAuthDecorator` reject such requests 
(`UNAUTHENTICATED` / `401`); `x-claims` / `x-user-name` / `x-gateway-id` are no 
longer read.
   - `AuthTokenExtractor` builds the `AuthzToken` claims map from the verified 
token only. `UserContext` and its readers are unchanged.
   - Adds `JwtVerifierTest` (pure identity-derivation unit tests).
   
   **SDK (`airavata-python-sdk`)** — sends only the Keycloak access token 
(Bearer) across the facade, all service clients, the transport layer, and the 
experiment/Jupyter helpers; no `x-claims`.
   
   **Keycloak** — adds the public `pga-public` client (Authorization Code + 
PKCE) for browser clients.
   
   **Build** — the Tilt build step runs `mvn clean install` to avoid stale 
generated sources.
   
   ### Test plan
   - `mvn test -pl airavata-server -Dtest=JwtVerifierTest` — green.
   - Live: a raw Keycloak token (no `x-claims`) returns the user's data; 
garbage / tampered / expired tokens return `401`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to