[ 
https://issues.apache.org/jira/browse/KNOX-3467?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sandor Molnar updated KNOX-3467:
--------------------------------
    Summary: Implement and E2E-test requested-scope authorization for token 
exchange (KNOX-3455 Bucket 3, blocked — no product support yet)  (was: mplement 
and E2E-test requested-scope authorization for token exchange (KNOX-3455 Bucket 
3, blocked — no product support yet))

> Implement and E2E-test requested-scope authorization for token exchange 
> (KNOX-3455 Bucket 3, blocked — no product support yet)
> ------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: KNOX-3467
>                 URL: https://issues.apache.org/jira/browse/KNOX-3467
>             Project: Apache Knox
>          Issue Type: Sub-task
>          Components: CI, Tests
>    Affects Versions: 3.1.0
>            Reporter: Sandor Molnar
>            Assignee: Sandor Molnar
>            Priority: Major
>             Fix For: 3.1.0
>
>
> h2. Summary
> The KNOX-3455 acceptance-criteria list (master list on KNOX-3455) includes
> requested-scope behavior for RFC 8693 token exchange. *No product code 
> implements*
> {*}this today{*}, so it cannot be tested end-to-end. This issue tracks the 
> E2E CI coverage that depends on it. The missing product capability Jira will 
> be linked here later.
> h2. Current state
>  * The {{delegation.requested.scope.enabled}} provider parameter was 
> *removed* in
> KNOX-3457 because it did nothing.
>  * On the exchange path, {{scope}} is not parsed, not validated, and not 
> minted — no
> minted Knox token has ever carried a {{scope}} claim.
>  * Therefore the scope-related KNOX-3455 ACs are untestable until requesting 
> scope
> becomes a real, live capability.
> h2. Blocked acceptance criteria (from the KNOX-3455 master list)
>  # A requested scope that is not among the subject token's scopes is rejected 
> with {{{}invalid_scope{}}}.
>  # The minted token carries the correct {{scope}} claim (the {{scope}} field 
> of the "same-subject exchange returns correct 
> sub/aud/iss/scope/issued_token_type" AC).
>  # The "× no / all / some requested scopes" permutation axis of the exchange 
> ACs.
> h2. Work required
>  # {*}Product{*}: implement requested-scope handling on the token-exchange 
> path — parse the RFC 8693 {{scope}} parameter, authorize it against the 
> subject token's scopes, reject unauthorized scopes with 
> {{{}invalid_scope{}}}, and mint the {{scope}} claim onto the issued token. 
> (This likely warrants its own feature/design discussion and may be split out.)
>  # {*}Test{*}: once the above lands, add Docker-based E2E CI coverage using 
> the KNOX-3449 framework — *no separate docker compose* — with topology files 
> wired into {{.github/workflows/build/Dockerfile}} and auto-discovered 
> {{test_*.py}} scripts.
> h2. Dependencies
>  * Blocked until requesting scope is implemented on the exchange path (item 1 
> above).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to