smolnar82 commented on code in PR #1405:
URL: https://github.com/apache/knox/pull/1405#discussion_r4034186229
##########
gateway-provider-security-jwt/src/test/java/org/apache/knox/gateway/provider/federation/jwt/filter/TokenExchangeHandlerTest.java:
##########
@@ -571,6 +560,74 @@ public void
testNoResourceOrAudienceLeavesRequestAttributeUnset() throws Excepti
assertFalse(requestedAudiencesAttr.hasCaptured());
}
+ @Test
+ public void testSameSubjectRequestedAudienceIgnoredWhenFlagDisabled() throws
Exception {
+ // Fail-safe default: for a same-subject exchange the requested audience
is dropped entirely
+ // (not conveyed downstream), so a passthrough audience validator cannot
mint an
+ // arbitrarily-audienced token without authorization. The exchange still
succeeds.
+ filter.valid.put("subtok", jwtWithAudiences("alice", "KNOXSSO",
"service-a"));
+ handler.handle(exchangeRequest("subtok", null, new String[]
{"service-a"}), response, chain);
+
+ assertTrue(filter.continued);
+ assertFalse(requestedAudiencesAttr.hasCaptured());
+ }
+
+ @Test
+ public void
testSameSubjectRequestedAudienceAuthorizedWhenSubsetOfSubjectTokenAudience()
throws Exception {
+ // Honoring on: a requested audience the subject token already carries is
authorized and
+ // conveyed, even when the subject token carries additional audiences.
+ filter.delegationSameSubjectRequestedAudienceEnabled = true;
+ filter.valid.put("subtok", jwtWithAudiences("alice", "KNOXSSO",
"service-a", "service-b", "service-c"));
+ handler.handle(exchangeRequest("subtok", null, new String[]
{"service-a"}), response, chain);
+
+ assertTrue(filter.continued);
+ assertEquals(Arrays.asList("service-a"),
requestedAudiencesAttr.getValue());
+ }
+
+ @Test
+ public void
testSameSubjectRequestedAudienceRejectedWhenNotInSubjectTokenAudience() throws
Exception {
+ // Honoring on but the requested audience is not among the subject token's
own aud claim:
+ // rejected as invalid_target and never conveyed.
+ filter.delegationSameSubjectRequestedAudienceEnabled = true;
+ filter.valid.put("subtok", jwtWithAudiences("alice", "KNOXSSO",
"service-a"));
+ handler.handle(exchangeRequest("subtok", null, new String[]
{"service-b"}), response, chain);
+
+ assertFalse(filter.continued);
+ assertEquals(HttpServletResponse.SC_BAD_REQUEST, filter.errorStatus);
+ assertEquals("invalid_target", filter.error);
+ assertFalse(requestedAudiencesAttr.hasCaptured());
+ }
+
+ @Test
+ public void
testSameSubjectRequestedAudienceRejectedWhenSubjectTokenHasNoAudience() throws
Exception {
+ // Honoring on and a requested audience present, but the subject token
carries no aud claim:
+ // there is nothing to authorize against, so the request is rejected.
+ filter.delegationSameSubjectRequestedAudienceEnabled = true;
+ filter.valid.put("subtok", jwt("alice", "KNOXSSO"));
+ handler.handle(exchangeRequest("subtok", null, new String[]
{"service-a"}), response, chain);
+
+ assertFalse(filter.continued);
+ assertEquals(HttpServletResponse.SC_BAD_REQUEST, filter.errorStatus);
+ assertEquals("invalid_target", filter.error);
+ assertFalse(requestedAudiencesAttr.hasCaptured());
+ }
Review Comment:
Will add a boundary test where some requested audiences are in the subject
token's `aud` and some aren't, asserting it's rejected, which confirms all
values are checked, not just one.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]