[
https://issues.apache.org/jira/browse/KNOX-3395?focusedWorklogId=1031964&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1031964
]
ASF GitHub Bot logged work on KNOX-3395:
----------------------------------------
Author: ASF GitHub Bot
Created on: 24/Jul/26 06:08
Start Date: 24/Jul/26 06:08
Worklog Time Spent: 10m
Work Description: Raghav-Mah3shwari opened a new pull request, #1325:
URL: https://github.com/apache/knox/pull/1325
## What changes were proposed in this pull request?
This PR adds a new Docker Compose integration test suite that covers the
`knoxtoken` topology (JWTProvider federation) and the KNOXTOKEN token-issuance
service. Both are baked into the CI test image but were previously exercised by
**no** integration test.
New file: `.github/workflows/tests/test_knoxtoken_jwt.py`
It validates a real end-to-end token flow:
1. Mint a Knox JWT from the KNOXTOKEN service
(`gateway/knoxldap/knoxtoken/api/v1/token`) using Basic auth.
2. Present that bearer token to the JWTProvider-protected topology
(`gateway/knoxtoken/auth/api/v1/pre`) and confirm the caller identity is
asserted.
Test cases:
- `test_token_endpoint_returns_jwt_and_metadata` — token response contains
`access_token`, `token_type: Bearer`, `expires_in`, and the token is a
well-formed 3-segment JWT.
- `test_token_requires_authentication` — anonymous token request returns 401.
- `test_jwt_grants_access_to_federated_topology` — a valid JWT authenticates
and yields `x-knox-actor-username: guest`.
- `test_federated_topology_requires_token` — a request with no token returns
401.
- `test_federated_topology_rejects_invalid_token` — a malformed bearer token
returns 401.
The suite reuses the existing `common_utils` helpers and follows the current
test style. It does not overlap with existing tests: all other suites use Basic
auth or preauth headers, and none issue a Knox token or authenticate via
JWTProvider.
No production code, topologies, or workflow behavior are changed.
## How was this patch tested?
- Verified endpoint paths and contract against the codebase before writing:
- KNOXTOKEN path `knoxtoken/api/v1/token` and JSON keys `access_token` /
`token_type` / `expires_in`
(`gateway-service-knoxtoken/.../TokenResource.java`).
- Auth service path `auth/api/v1/pre`
(`gateway-service-auth/.../PreAuthResource.java`).
- `knoxtoken.xml` uses `JWTProvider` with `RS256`, matching the gateway's
default token signing algorithm.
- The new file is auto-discovered by the default `pytest` run in
`docker-compose.yml` (it is not in the single-EKU `--ignore` list), so it
executes as part of the existing Docker Compose test job.
- Locally, the suite can be run with:
```bash
docker compose -f ./.github/workflows/compose/docker-compose.yml up -d
docker compose -f ./.github/workflows/compose/docker-compose.yml run --rm
tests
```
## Integration Tests
This PR is itself an addition of integration tests under
`.github/workflows/tests`. No Java unit tests are added because the change only
introduces black-box HTTP integration tests against the packaged gateway; the
underlying KNOXTOKEN and JWTProvider components already have Java unit coverage
in their respective modules.
## UI changes
N/A — no UI changes.
Issue Time Tracking
-------------------
Worklog Id: (was: 1031964)
Remaining Estimate: 0h
Time Spent: 10m
> Add KNOXTOKEN issuance and JWTProvider federation integration tests
> -------------------------------------------------------------------
>
> Key: KNOX-3395
> URL: https://issues.apache.org/jira/browse/KNOX-3395
> Project: Apache Knox
> Issue Type: Task
> Reporter: Raghav Maheshwari
> Priority: Major
> Time Spent: 10m
> Remaining Estimate: 0h
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)