[
https://issues.apache.org/jira/browse/KNOX-3459?focusedWorklogId=1041668&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1041668
]
ASF GitHub Bot logged work on KNOX-3459:
----------------------------------------
Author: ASF GitHub Bot
Created on: 15/Sep/26 13:10
Start Date: 15/Sep/26 13:10
Worklog Time Spent: 10m
Work Description: smolnar82 opened a new pull request, #1401:
URL: https://github.com/apache/knox/pull/1401
[KNOX-3459](https://issues.apache.org/jira/browse/KNOX-3459) - Honor
delegation policy tokenTtlSec
## What changes were proposed in this pull request?
`PolicyDecision.getEffectiveTtlSec()` is already computed by
`JdbcDelegationPolicyService.evaluate()` (from
`DelegationPolicy.getTokenTtlSec()`, falling back to the configured default),
but it was silently discarded — `TokenExchangeHandler` read only
`getDenyReason()`, so the per-policy TTL had no effect on the minted token's
lifetime.
This plumbs the effective TTL to KNOXTOKEN, mirroring the existing audience
passthrough:
- **`CommonTokenConstants`** — adds `REQUESTED_TTL_REQUEST_ATTR`
(`knox.token.requested.ttl`), an `Integer` seconds value an upstream component
may set.
- **`TokenExchangeHandler`** — on the authorized delegation path (OBO /
headless), sets the attribute from `policyDecision.getEffectiveTtlSec()`.
- **`TokenResource.getExpiry()`** — when the attribute is present and
positive, uses it as the expiry basis directly, deliberately bypassing the
topology `knox.token.ttl` upper bound and the client `lifespan` clamp.
The policy TTL is authoritative because `DelegationPolicy.tokenTtlSec` is
trusted, operator-configured server-side state (a peer of the topology config,
not untrusted client input like `lifespan`). Its main use case — longer-lived
tokens for headless/batch delegations — is impossible if capped by the topology
default. Plain (same-subject) exchanges are unaffected: the attribute is set
only on the policy-governed delegation path.
## How was this patch tested?
- `TokenExchangeHandlerTest` (66 → 69): OBO delegation conveys the policy
TTL, headless delegation conveys it, same-subject exchange does not.
- `TokenServiceResourceTest` (101 → 103): minted token honors the policy TTL
while bypassing a lower topology `knox.token.ttl` cap, and bypasses a shorter
`lifespan` clamp.
- Both modules compile clean; full suites green.
Issue Time Tracking
-------------------
Worklog Id: (was: 1041668)
Remaining Estimate: 0h
Time Spent: 10m
> Honor delegation policy tokenTtlSec override when minting exchanged tokens
> --------------------------------------------------------------------------
>
> Key: KNOX-3459
> URL: https://issues.apache.org/jira/browse/KNOX-3459
> Project: Apache Knox
> Issue Type: Sub-task
> Components: Server
> Affects Versions: 3.1.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Major
> Fix For: 3.1.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> {{PolicyDecision.getEffectiveTtlSec() }}is already computed by
> J{{{}dbcDelegationPolicyService.evaluate(){}}} (from
> {{DelegationPolicy.getTokenTtlSec(),}} falling back to the configured
> default), but it is silently discarded: TokenExchangeHandler reads only
> {{{}getDenyReason(){}}}. The per-policy TTL therefore has no effect on the
> minted token's lifetime.
> {*}Scope{*}: plumb the effective TTL to KNOXTOKEN, mirroring the existing
> audience passthrough: add a request-attribute constant to
> {{CommonTokenConstants}} (e.g. {{{}REQUESTED_TTL_REQUEST_ATTR{}}}), set it in
> {{TokenExchangeHandler}} from {{{}policyDecision.getEffectiveTtlSec(){}}},
> and consume it in T{{{}okenResource.getExpiry(){}}} (which today only honors
> the lifespan param and the topology {{knox.token.ttl }}cap).
> The policy TTL is authoritative: for exchange-originated mints it becomes the
> expiry basis directly and must bypass the topology {{knox.token.ttl}}
> upper-bound / lifespan clamp in {{{}getExpiry(){}}}, rather than flow through
> it.
> Rationale: {{DelegationPolicy.tokenTtlSec}} is trusted, operator-configured
> server-side state (a peer of the topology config, not untrusted client input
> like lifespan), and its main use case - longer-lived tokens for
> headless/batch delegations - is impossible if capped by the topology default
> (which would also make it redundant with the existing lifespan shorten-only
> behavior). The effective TTL fallback is already resolved upstream
> ({{{}evaluate(){}}} sets {{effectiveTtlSec}} to {{policy.getTokenTtlSec()}}
> or {{{}config.getDelegationServiceTokenTtlSec(){}}}), so {{TokenResource}}
> simply honors the value it receives.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)