[ 
https://issues.apache.org/jira/browse/KNOX-3395?focusedWorklogId=1034723&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1034723
 ]

ASF GitHub Bot logged work on KNOX-3395:
----------------------------------------

                Author: ASF GitHub Bot
            Created on: 10/Aug/26 10:03
            Start Date: 10/Aug/26 10:03
    Worklog Time Spent: 10m 
      Work Description: smolnar82 commented on code in PR #1325:
URL: https://github.com/apache/knox/pull/1325#discussion_r3748436525


##########
.github/workflows/build/gateway.sh:
##########
@@ -34,7 +34,9 @@ keytool -genkeypair -alias ldaps -keyalg RSA -keysize 2048 \
 # 2) Store the keystore password under the alias the LDAP SSL config resolves.
 /knox-runtime/bin/knoxcli.sh create-alias "$KEYSTORE_PASSWORD_ALIAS" --value 
"$KEYSTORE_PASSWORD"
 
-# 3) Trust that certificate in the JVM default truststore (cacerts) so the 
JNDI-based
+# 3) Provision the gateway-level JWK required for server-managed Knox token 
state
+#    (renew / revoke / enable / disable and JWTProvider enforcement).
+/knox-runtime/bin/knoxcli.sh generate-jwk --jwkAlg HS256 --saveAlias 
knox.token.hash.key

Review Comment:
   The comment change here is misleading. Yuo removed the original 
   >  Trust that certificate in the JVM default truststore (cacerts) so the 
JNDI-based
   Shiro LDAP realm accepts it. This is additive - it does not remove the 
default CAs.
   
   before the `keytool` command.
   
   I thinks it should look like this:
   > \# 3) Provision the gateway-level JWK required for server-managed Knox 
token state (renew / revoke / enable / disable and JWTProvider enforcement).
   /knox-runtime/bin/knoxcli.sh generate-jwk --jwkAlg HS256 --saveAlias 
knox.token.hash.key
   
   > \# 4) Trust that certificate in the JVM default truststore (cacerts) so 
the JNDI-based
   Shiro LDAP realm accepts it. This is additive - it does not remove the 
default CAs.
   keytool -exportcert -alias ldaps -rfc \
     -keystore "$KEYSTORE" -storepass "$KEYSTORE_PASSWORD" -file 
/tmp/ldaps-cert.pem



##########
.github/workflows/tests/test_knoxtoken_jwt.py:
##########
@@ -0,0 +1,292 @@
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements.  See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to you under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License.  You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+
+"""End-to-end tests for KNOXTOKEN issuance, lifecycle, and JWTProvider 
federation.
+
+These exercise the ``knoxtoken`` topology (JWTProvider federation) together
+with the KNOXTOKEN service exposed by the ``knoxldap`` topology:
+
+1. A JWT is minted from the KNOXTOKEN service using Basic auth (knoxldap).
+2. The resulting bearer token is presented to the JWTProvider-protected
+   ``knoxtoken`` topology, which must accept it and assert the caller's
+   identity.
+3. Lifecycle operations (renew / revoke / enable / disable) require
+   ``knox.token.exp.server-managed=true`` on both the issuing service and
+   the JWTProvider so that revocation and disablement are enforced at
+   federation time — not just acknowledged by the management API.
+
+No other suite issues Knox tokens or authenticates via JWTProvider, so this
+file does not overlap with the Basic-auth / preauth coverage elsewhere.
+"""
+
+import unittest
+
+from requests.auth import HTTPBasicAuth
+
+from common_utils import gateway_base_url, knox_delete, knox_get, knox_put
+
+
+class TestKnoxTokenJwt(unittest.TestCase):
+    """Mint a Knox JWT and use it against a JWTProvider-federated topology."""
+
+    def setUp(self):
+        self.base_url = gateway_base_url()
+        # KNOXTOKEN service lives in the knoxldap topology (Basic auth in 
front).
+        self.token_url = self.base_url + 
"gateway/knoxldap/knoxtoken/api/v1/token"
+        # Non-deprecated lifecycle paths (PUT renew / DELETE revoke).
+        self.token_v2_url = self.base_url + 
"gateway/knoxldap/knoxtoken/api/v2/token"
+        # JWTProvider-protected auth service in the knoxtoken topology.
+        self.federated_pre_url = self.base_url + 
"gateway/knoxtoken/auth/api/v1/pre"
+
+        self.guest_auth = HTTPBasicAuth("guest", "guest-password")
+        self.admin_auth = HTTPBasicAuth("admin", "admin-password")
+
+    def _issue_token(self, auth):
+        """Return the parsed JSON body of a freshly issued Knox token."""
+        response = knox_get(self.token_url, auth=auth)
+        self.assertEqual(
+            response.status_code,
+            200,
+            msg=f"Token issuance failed: {response.status_code} 
{response.text}",
+        )
+        payload = response.json()
+        self.assertIn("access_token", payload)
+        self.assertIn("token_id", payload)
+        return payload
+
+    def _federate(self, access_token):
+        """Present a bearer token to the JWTProvider-protected topology."""
+        return knox_get(
+            self.federated_pre_url,
+            headers={"Authorization": f"Bearer {access_token}"},
+        )
+
+    def _assert_federates(self, access_token, expected_username):
+        response = self._federate(access_token)
+        self.assertEqual(
+            response.status_code,
+            200,
+            msg=f"JWT was not accepted: {response.status_code} 
{response.text}",
+        )
+        self.assertEqual(
+            response.headers.get("x-knox-actor-username"),
+            expected_username,
+        )
+
+    def assert_federation_rejected(self, access_token):

Review Comment:
   Every other helper in the class uses a `_` prefix (`_issue_token`, 
`_federate`, `_assert_federates`). `assert_federation_rejected` is the only 
exception; it'll also show up in test discovery frameworks as a test method 
(they scan for names starting with `assert`). Please rename to 
`_assert_federation_rejected`.





Issue Time Tracking
-------------------

    Worklog Id:     (was: 1034723)
    Time Spent: 1h 10m  (was: 1h)

> Add KNOXTOKEN issuance and JWTProvider federation integration tests
> -------------------------------------------------------------------
>
>                 Key: KNOX-3395
>                 URL: https://issues.apache.org/jira/browse/KNOX-3395
>             Project: Apache Knox
>          Issue Type: Task
>            Reporter: Raghav Maheshwari
>            Priority: Major
>          Time Spent: 1h 10m
>  Remaining Estimate: 0h
>




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to