Sandor Molnar created KNOX-3493:
-----------------------------------
Summary: k8s delegation E2E: policy-enforced SA actor-token
delegation and headless SA-subject requested_subject exchange
Key: KNOX-3493
URL: https://issues.apache.org/jira/browse/KNOX-3493
Project: Apache Knox
Issue Type: Bug
Components: Server
Affects Versions: 3.1.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.1.0
*Description*
Add the two token-exchange E2E scenarios that depend on delegation-policy
enforcement in the exchange path - actor-token (on-behalf-of) delegation and
headless (requested_subject) exchange. These cannot be tested against the
currently-merged backend: TokenExchangeHandler builds a delegation Subject but
performs no DelegationPolicyService.evaluate check, and there is no
requested_subject/headless handling at all. This sub-task lands once that
backend work merges, reusing the harness delivered by the sibling ticket.
*In scope*
Extend test_k8s_delegation.py (harness from the sibling ticket) with the
delegation + headless scenarios below, including both the policy-allows (200)
and policy-denies (403) cases.
Seed delegation policies as part of test setup via the admin API (or the
compose bootstrap) so the allow/deny paths are deterministic.
*Out of scope*
Harness, CA/issuer export, KNOXIDF_ADMIN topology, same-subject exchange, and
negative-path tests — all delivered by the sibling ticket.
The backend enforcement + requested_subject/headless implementation itself —
tracked under the in-flight backend work (see Dependencies); this ticket is
tests only.
*Acceptance criteria*
* (AC4) A delegation exchange with an SA actor_token + a Knox-user
subject_token succeeds with HTTP 200 when a matching delegation policy exists,
and is rejected with HTTP 403 when no policy matches.
* (AC5) A headless exchange with an SA subject_token + requested_subject
succeeds with HTTP 200 when policy allows headless delegation, and is rejected
when it does not.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)