Sandor Molnar created KNOX-3459:
-----------------------------------

             Summary: Honor delegation policy tokenTtlSec override when minting 
exchanged tokens
                 Key: KNOX-3459
                 URL: https://issues.apache.org/jira/browse/KNOX-3459
             Project: Apache Knox
          Issue Type: Sub-task
          Components: Server
    Affects Versions: 3.1.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 3.1.0


{{PolicyDecision.getEffectiveTtlSec() }}is already computed by 
J{{{}dbcDelegationPolicyService.evaluate(){}}} (from 
{{DelegationPolicy.getTokenTtlSec(),}} falling back to the configured default), 
but it is silently discarded: TokenExchangeHandler reads only 
{{{}getDenyReason(){}}}. The per-policy TTL therefore has no effect on the 
minted token's lifetime.

{*}Scope{*}: plumb the effective TTL to KNOXTOKEN, mirroring the existing 
audience passthrough: add a request-attribute constant to 
{{CommonTokenConstants}} (e.g. {{{}REQUESTED_TTL_REQUEST_ATTR{}}}), set it in 
{{TokenExchangeHandler}} from {{{}policyDecision.getEffectiveTtlSec(){}}}, and 
consume it in T{{{}okenResource.getExpiry(){}}} (which today only honors the 
lifespan param and the topology {{knox.token.ttl }}cap).

The policy TTL is authoritative: for exchange-originated mints it becomes the 
expiry basis directly and must bypass the topology {{knox.token.ttl}} 
upper-bound / lifespan clamp in {{{}getExpiry(){}}}, rather than flow through 
it.

Rationale: {{DelegationPolicy.tokenTtlSec}} is trusted, operator-configured 
server-side state (a peer of the topology config, not untrusted client input 
like lifespan), and its main use case - longer-lived tokens for headless/batch 
delegations - is impossible if capped by the topology default (which would also 
make it redundant with the existing lifespan shorten-only behavior). The 
effective TTL fallback is already resolved upstream ({{{}evaluate(){}}} sets 
{{effectiveTtlSec}} to {{policy.getTokenTtlSec()}} or 
{{{}config.getDelegationServiceTokenTtlSec(){}}}), so {{TokenResource}} simply 
honors the value it receives.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to