[ 
https://issues.apache.org/jira/browse/KNOX-3455?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sandor Molnar updated KNOX-3455:
--------------------------------
    Description: 
As a KNOXIDF client, I want CI evidence that same-subject token exchange works 
end-to-end through a running Knox gateway, so that I can validate the 
capability before integrating my service.

ACCEPTANCE CRITERIA:
 # A new integration test file for token exchange is added and runs in the 
default CI build.
 # A successful same-subject exchange returns correct sub, aud, iss, scope, and 
issued_token_type values in the issued token.
 # A successful same subject with no act claim exchange where no scopes are 
present in the subject token passes.
 # A successful same subject with no act claim exchange where all requested 
scopes are present in the subject token passes.
 # A successful same subject with no act claim and no requested scopes passes.
 # A successful same subject with act claim and no requested scopes passes.
 # A successful same subject with act claim and requested scope and
 # A request missing the audience parameter returns HTTP 400 with error code 
invalid_request.
 # A request with multiple audience values returns HTTP 400 with error code 
invalid_request.
 # A request where the subject token has no act cliam and has an audience claim 
that is a full token prefix of the requested audience passes.
 # A request where the subject token has no act claim and has an audience claim 
that is not a full token prefix of the requested audience returns error code 
invalid_scope.
 # A request where the requested audience is not in the subject token's aud 
claim returns error code invalid_scope.
 # A request where the subject token has scopes defined and a requested scope 
is not in the subject token returns error code invalid_scope.
 # A cross-subject attempt using the topology with delegation disabled returns 
an error indicating delegation is not permitted.
 # A same-subject exchange against the delegation-enabled topology succeeds 
normally.
 # The delegation topology file and the same-subject-only topology file are 
added to the CI Dockerfile.

  was:
As a KNOXIDF client, I want CI evidence that same-subject token exchange works 
end-to-end through a running Knox gateway, so that I can validate the 
capability before integrating my service.

ACCEPTANCE CRITERIA:
 # A new integration test file for token exchange is added and runs in the 
default CI build.

 # A successful same-subject exchange returns correct sub, aud, iss, scope, and 
issued_token_type values in the issued token.

 # A successful same subject with no act claim exchange where no scopes are 
present in the subject token passes.

 # A successful same subject with no act claim exchange where all requested 
scopes are present in the subject token passes.

 # A successful same subject with no act claim and no requested scopes passes.

 # A successful same subject with act claim and no requested scopes passes.

 # A successful same subject with act claim and requested scope and

 # A request missing the audience parameter returns HTTP 400 with error code 
invalid_request.

 # A request with multiple audience values returns HTTP 400 with error code 
invalid_request.

 # A request where the subject token has no act cliam and has an audience claim 
that is a full token prefix of the requested audience passes.

 # A request where the subject token has no act claim and has an audience claim 
that is not a full token prefix of the requested audience returns error code 
invalid_scope.

 # A request where the requested audience is not in the subject token's aud 
claim returns error code invalid_scope.

 # A request where the subject token has scopes defined and a requested scope 
is not in the subject token returns error code invalid_scope.

 # A cross-subject attempt using the topology with delegation disabled returns 
an error indicating delegation is not permitted.

 # A same-subject exchange against the delegation-enabled topology succeeds 
normally.

 # The delegation topology file and the same-subject-only topology file are 
added to the CI Dockerfile.


> CI Gate - Same-Subject Token Exchange End-to-End Tests Pass in Default CI Run
> -----------------------------------------------------------------------------
>
>                 Key: KNOX-3455
>                 URL: https://issues.apache.org/jira/browse/KNOX-3455
>             Project: Apache Knox
>          Issue Type: Task
>          Components: CI
>            Reporter: Sandor Molnar
>            Assignee: Sandor Molnar
>            Priority: Major
>             Fix For: 3.1.0
>
>
> As a KNOXIDF client, I want CI evidence that same-subject token exchange 
> works end-to-end through a running Knox gateway, so that I can validate the 
> capability before integrating my service.
> ACCEPTANCE CRITERIA:
>  # A new integration test file for token exchange is added and runs in the 
> default CI build.
>  # A successful same-subject exchange returns correct sub, aud, iss, scope, 
> and issued_token_type values in the issued token.
>  # A successful same subject with no act claim exchange where no scopes are 
> present in the subject token passes.
>  # A successful same subject with no act claim exchange where all requested 
> scopes are present in the subject token passes.
>  # A successful same subject with no act claim and no requested scopes passes.
>  # A successful same subject with act claim and no requested scopes passes.
>  # A successful same subject with act claim and requested scope and
>  # A request missing the audience parameter returns HTTP 400 with error code 
> invalid_request.
>  # A request with multiple audience values returns HTTP 400 with error code 
> invalid_request.
>  # A request where the subject token has no act cliam and has an audience 
> claim that is a full token prefix of the requested audience passes.
>  # A request where the subject token has no act claim and has an audience 
> claim that is not a full token prefix of the requested audience returns error 
> code invalid_scope.
>  # A request where the requested audience is not in the subject token's aud 
> claim returns error code invalid_scope.
>  # A request where the subject token has scopes defined and a requested scope 
> is not in the subject token returns error code invalid_scope.
>  # A cross-subject attempt using the topology with delegation disabled 
> returns an error indicating delegation is not permitted.
>  # A same-subject exchange against the delegation-enabled topology succeeds 
> normally.
>  # The delegation topology file and the same-subject-only topology file are 
> added to the CI Dockerfile.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to