[ 
https://issues.apache.org/jira/browse/SPARK-59270?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated SPARK-59270:
-----------------------------------
    Labels: pull-request-available  (was: )

> Run the JWT auth end-to-end walkthrough in CI
> ---------------------------------------------
>
>                 Key: SPARK-59270
>                 URL: https://issues.apache.org/jira/browse/SPARK-59270
>             Project: Spark
>          Issue Type: Sub-task
>          Components: Connect
>    Affects Versions: connect-gateway-0.1.0
>            Reporter: L. C. Hsieh
>            Assignee: L. C. Hsieh
>            Priority: Major
>              Labels: pull-request-available
>
> The deploy/examples/e2e-auth-jwt walkthrough is the only thing that exercises 
> the
> Helm chart's auth block end to end. The in-process tests cover 
> JwtAuthenticator
> itself, but nothing rendered the chart's auth.type: jwt ConfigMap or drove a 
> real
> PySpark client through the bearer-token transport, so a break in the chart's 
> auth
> templating or in claim propagation would go unnoticed.
> This adds an e2e-auth-jwt job to the E2E workflow, running in parallel with
> e2e-smoke on its own kind cluster. It asserts:
>   - The chart renders auth.type: jwt with the expected issuer and claim 
> mapping
>     (tenant_claim, groups_claim).
>     audit pipeline: the session.create event must report user_id=alice (not
>     anonymous), tenant=team-a, groups=devs,admins.
>   - Three rejection paths fail with UNAUTHENTICATED: an expired token, a 
> token signed
>     with the wrong secret, and no token at all.
>   - Signature-validation failures all report the same generic "invalid JWT" 
> message.
>     This is a deliberate property — a verifier that distinguishes "expired" 
> from "bad
>     signature" tells an attacker which half to work on — so it is asserted, 
> not just
>     observed.
>   - The auth.failure audit events use only the fixed reason values 
> invalid_token and
>     missing_token, and scg_auth_failures_total counts both.
>     
> Tokens are signed with an 8-line openssl helper taken from the walkthrough; 
> no JWT
> library is needed. PySpark is pinned to 4.0.0 to match the backend image, as 
> in the
> e2e-smoke job.
>   
> Verified by running the whole walkthrough locally first: the chart rendered 
> the
> expected auth block, the valid token produced user_id=alice in the audit log, 
> all
> three rejection paths returned UNAUTHENTICATED with the expected messages, 
> and the
> audit reasons and metrics matched (invalid_token x4, missing_token x2).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to