madhushreeag commented on code in PR #44365:
URL: https://github.com/apache/superset/pull/44365#discussion_r4199330073


##########
superset/security/login_token.py:
##########
@@ -0,0 +1,334 @@
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements.  See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership.  The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License.  You may obtain a copy of the License at
+#
+#   http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied.  See the License for the
+# specific language governing permissions and limitations
+# under the License.
+"""One-time login tokens for establishing a session inside an iframe.
+
+An SSO redirect flow cannot run inside an iframe: identity providers commonly
+refuse to be framed, and the redirect chain depends on cookies that browsers
+treat as third-party in an embedded context. A parent application that already
+holds a trustworthy proof of the user's identity uses these tokens to turn that
+proof into an ordinary Superset session in two steps:
+
+1. its backend mints a token, presenting a credential that an operator-supplied
+   resolver validates (server-to-server, so the credential never reaches the
+   browser), and
+2. the browser navigates the iframe to the consume endpoint, which exchanges 
the
+   token for a session cookie.
+
+The token is an opaque handle to a short-lived server-side record; no identity
+data travels in the URL.
+
+**This module must stay importable from ``superset_config.py``.** The 
documented
+way to write a resolver begins with ``from superset.security.login_token import
+LoginTokenUserInfo``, and the config is read before the application is
+initialized. Anything reaching ``superset.models`` -- the key-value DAO and its
+model both do, via ``superset.models.helpers`` -- builds encrypted columns and
+``relationship(security_manager.user_model, ...)`` at class-definition time and
+raises "App not initialized yet". Those imports are therefore deferred into the
+functions that need them; ``key_value.types`` and ``key_value.utils`` pull in 
no
+models and are safe at module scope.
+"""
+
+from __future__ import annotations
+
+import logging
+import re
+from datetime import datetime, timedelta
+from typing import Any, Callable, cast, TypedDict
+from uuid import UUID, uuid4
+
+from flask import current_app, Request
+
+from superset.key_value.types import JsonKeyValueCodec, KeyValueResource
+from superset.key_value.utils import get_filter
+
+logger = logging.getLogger(__name__)
+
+LOGIN_TOKEN_RESOURCE = KeyValueResource.LOGIN_TOKEN
+LOGIN_TOKEN_CODEC = JsonKeyValueCodec()
+
+# Kept short deliberately: the token is handed to a browser as an iframe URL, 
so
+# it lands in access logs and the parent page's DOM. A lifetime measured in
+# seconds bounds the window in which an observer could replay it.
+DEFAULT_LOGIN_TOKEN_TTL_SECONDS = 60
+
+
+class LoginTokenUserInfo(TypedDict, total=False):
+    """The identity a resolver returns for a one-time login token.
+
+    This mirrors the ``userinfo`` contract of Flask-AppBuilder's
+    ``auth_user_oauth``, which the consume step delegates to. ``username``
+    identifies the user, falling back to ``email`` when absent. ``role_keys`` 
are
+    resolved through ``AUTH_ROLES_MAPPING``, so a caller can only ever request
+    roles the operator has already mapped -- authorization stays with the
+    operator rather than moving to the parent application.
+    """
+
+    username: str
+    email: str
+    first_name: str
+    last_name: str
+    role_keys: list[str]
+
+
+LoginTokenIdentityResolver = Callable[..., LoginTokenUserInfo | None]
+
+# Characters a WHATWG URL parser strips before resolving, plus their
+# percent-encoded forms, which some browsers also remove when following a
+# Location header. Normalizing them first stops `/\tx` or `/%09x` smuggling a
+# different target past the checks below.
+_URL_STRIPPED_CONTROL_CHARS = re.compile(r"[\t\n\r]|%09|%0[ADad]")
+
+
+def is_safe_next_path(url: str) -> bool:
+    """Whether ``url`` is a site-relative path this endpoint may redirect to.
+
+    Deliberately stricter than :func:`superset.utils.link_redirect.
+    is_safe_redirect_url`, which resolves "internal" against
+    ``WEBDRIVER_BASEURL`` / ``WEBDRIVER_BASEURL_USER_FRIENDLY``. Those are
+    report-worker settings defaulting to ``http://0.0.0.0:8080/`` and need bear
+    no relation to the public origin, so a deployment that has never configured
+    reports would see a legitimate same-origin absolute URL rejected and be
+    redirected to ``/`` instead of the requested dashboard.
+
+    Requiring a relative path avoids the question entirely: the parent
+    application always knows the path it wants, the browser resolves it against
+    Superset's own origin, and there is no host to compare.
+    """
+    if not url or not url.strip():
+        return False
+
+    normalized = _URL_STRIPPED_CONTROL_CHARS.sub("", url.strip())
+    # Browsers treat backslashes as forward slashes in special schemes, so
+    # `/\evil.com` would resolve as the protocol-relative `//evil.com`.
+    normalized = normalized.replace("\\", "/")
+
+    # A single leading slash, and nothing that could be read as a host or a
+    # scheme. `//host`, `https://host` and `mailto:x` are all rejected.
+    return normalized.startswith("/") and not normalized.startswith("//")
+
+
+def is_enabled() -> bool:
+    """Whether the flow is usable: feature flag on and a resolver 
configured."""
+    # Deferred: ``superset/__init__`` imports the app factory, so a 
module-level
+    # import here would be circular via superset.daos / superset.security.
+    from superset import (  # pylint: disable=import-outside-toplevel
+        is_feature_enabled,
+    )
+
+    if not is_feature_enabled("LOGIN_TOKEN"):
+        return False
+
+    return current_app.config.get("LOGIN_TOKEN_IDENTITY_RESOLVER") is not None
+
+
+def get_ttl_seconds() -> int:
+    """The configured token lifetime, falling back to the default."""
+    configured = current_app.config.get(
+        "LOGIN_TOKEN_TTL_SECONDS", DEFAULT_LOGIN_TOKEN_TTL_SECONDS
+    )
+    try:
+        ttl = int(configured)
+    except (TypeError, ValueError):
+        logger.warning(
+            "LOGIN_TOKEN_TTL_SECONDS is not an integer (%r); using %s",
+            configured,
+            DEFAULT_LOGIN_TOKEN_TTL_SECONDS,
+        )
+        return DEFAULT_LOGIN_TOKEN_TTL_SECONDS
+
+    return ttl if ttl > 0 else DEFAULT_LOGIN_TOKEN_TTL_SECONDS
+
+
+# Each rejection below is a distinct failure with its own diagnostic — an
+# unconfigured resolver is normal and silent, a misconfigured or misbehaving 
one
+# is logged. Merging the branches to satisfy the return-count limit would lose
+# that distinction, which is the only signal an operator gets.
+def resolve_identity(  # pylint: disable=too-many-return-statements
+    request: Request, **kwargs: Any
+) -> LoginTokenUserInfo | None:
+    """Run the operator-supplied resolver against an inbound mint request.
+
+    The resolver is the whole authentication boundary for minting: it decides
+    what counts as proof of identity (an OIDC id token, an existing session, a
+    credential checked against an internal service). A resolver that raises, or
+    returns something other than a mapping, is treated as a rejection rather
+    than a server error, so a failing validation can never be mistaken for a
+    successful one.
+    """
+    resolver = current_app.config.get("LOGIN_TOKEN_IDENTITY_RESOLVER")
+    if resolver is None:
+        return None
+
+    if not callable(resolver):
+        logger.error("LOGIN_TOKEN_IDENTITY_RESOLVER is not callable")
+        return None
+
+    try:
+        userinfo = resolver(request, **kwargs)
+    except Exception:  # pylint: disable=broad-except
+        logger.exception("LOGIN_TOKEN_IDENTITY_RESOLVER rejected the request")
+        return None
+
+    if not userinfo:
+        return None
+
+    if not isinstance(userinfo, dict):
+        # A truthy non-mapping would otherwise raise on the ``.get`` below and
+        # surface as a 500, contradicting the rejection contract above.
+        logger.error(
+            "LOGIN_TOKEN_IDENTITY_RESOLVER returned %s, expected a mapping",
+            type(userinfo).__name__,
+        )
+        return None
+
+    # Normalize before validating, because ``auth_user_oauth`` selects on key
+    # *presence* rather than truthiness: ``if "username" in userinfo`` wins 
even
+    # when the value is empty, and the empty username is then rejected 
outright.
+    # A resolver returning {"username": "", "email": "[email protected]"} would
+    # otherwise mint a perfectly good token that always fails redemption with a
+    # 401, instead of falling back to the email. Stripping and dropping empty
+    # string values keeps this check and FAB's in agreement.
+    userinfo = {
+        key: value.strip() if isinstance(value, str) else value

Review Comment:
   Yes, only dropping empty or whitespace-only values was needed, and trimming 
the non-empty ones was an identity change I added on top. Surviving values are 
now passed through byte for byte. I didn't add a check that rejects values 
changed by `strip()`, because it fails the same way in reverse and would refuse 
a padded username that really exists, while only the resolver knows which 
account it meant. The new 
`test_a_padded_username_does_not_authenticate_the_unpadded_account` checks that 
`"  gamma  "` gets a 401 and leaves the frame anonymous; with the `strip()` put 
back, it fails with a 302 logged in as `gamma`.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to