[
https://issues.apache.org/jira/browse/SPARK-59270?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated SPARK-59270:
-----------------------------------
Labels: pull-request-available (was: )
> Run the JWT auth end-to-end walkthrough in CI
> ---------------------------------------------
>
> Key: SPARK-59270
> URL: https://issues.apache.org/jira/browse/SPARK-59270
> Project: Spark
> Issue Type: Sub-task
> Components: Connect
> Affects Versions: connect-gateway-0.1.0
> Reporter: L. C. Hsieh
> Assignee: L. C. Hsieh
> Priority: Major
> Labels: pull-request-available
>
> The deploy/examples/e2e-auth-jwt walkthrough is the only thing that exercises
> the
> Helm chart's auth block end to end. The in-process tests cover
> JwtAuthenticator
> itself, but nothing rendered the chart's auth.type: jwt ConfigMap or drove a
> real
> PySpark client through the bearer-token transport, so a break in the chart's
> auth
> templating or in claim propagation would go unnoticed.
> This adds an e2e-auth-jwt job to the E2E workflow, running in parallel with
> e2e-smoke on its own kind cluster. It asserts:
> - The chart renders auth.type: jwt with the expected issuer and claim
> mapping
> (tenant_claim, groups_claim).
> audit pipeline: the session.create event must report user_id=alice (not
> anonymous), tenant=team-a, groups=devs,admins.
> - Three rejection paths fail with UNAUTHENTICATED: an expired token, a
> token signed
> with the wrong secret, and no token at all.
> - Signature-validation failures all report the same generic "invalid JWT"
> message.
> This is a deliberate property — a verifier that distinguishes "expired"
> from "bad
> signature" tells an attacker which half to work on — so it is asserted,
> not just
> observed.
> - The auth.failure audit events use only the fixed reason values
> invalid_token and
> missing_token, and scg_auth_failures_total counts both.
>
> Tokens are signed with an 8-line openssl helper taken from the walkthrough;
> no JWT
> library is needed. PySpark is pinned to 4.0.0 to match the backend image, as
> in the
> e2e-smoke job.
>
> Verified by running the whole walkthrough locally first: the chart rendered
> the
> expected auth block, the valid token produced user_id=alice in the audit log,
> all
> three rejection paths returned UNAUTHENTICATED with the expected messages,
> and the
> audit reasons and metrics matched (invalid_token x4, missing_token x2).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]