[
https://issues.apache.org/jira/browse/KNOX-3493?focusedWorklogId=1044576&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1044576
]
ASF GitHub Bot logged work on KNOX-3493:
----------------------------------------
Author: ASF GitHub Bot
Created on: 29/Sep/26 12:10
Start Date: 29/Sep/26 12:10
Worklog Time Spent: 10m
Work Description: smolnar82 opened a new pull request, #1434:
URL: https://github.com/apache/knox/pull/1434
[KNOX-3493](https://issues.apache.org/jira/browse/KNOX-3493) - k8s
delegation E2E: policy-enforced SA actor-token delegation and headless
requested_subject exchange
## What changes were proposed in this pull request?
Extends the k8s ServiceAccount delegation harness (`test_k8s_delegation.py`)
with the two policy-enforced RFC 8693 scenarios that were out of scope for the
sibling harness ticket:
- **AC4 — interactive delegation:** a k3s SA projected `actor_token` acting
on behalf of a Knox-user `subject_token`. Succeeds (HTTP 200) under a matching
`K8S_SA` delegation policy and is rejected (HTTP 400 `invalid_request`,
"rejected by policy") when the policy authorizes a different subject.
- **AC5 — headless delegation:** an SA `subject_token` +
`requested_subject`. Succeeds when the policy sets `allowHeadlessExchange=true`
and is rejected when it does not.
Policies are seeded per-test through the KNOXIDF_ADMIN delegation-policy
REST API via the existing `DelegationPolicyAdmin` helper; the SA actor key
(`K8S_SA`, `<iss>:<ns>:<sa-name>`) is derived from the token itself, mirroring
`ActorIdentity.fromJwt`. The exchange runs on the delegation-enabled
`knoxidf-token-delegation-policy` topology; success paths assert the minted
token records the impersonation (`sub` = impersonated user, nested `act.sub` =
SA identity, requested resource as `aud`). Issuer registration and seeded
policies are bracketed with `addCleanup`, so each test is self-contained
regardless of run order. No existing test or `delegation_helpers.py` was
modified.
## How was this patch tested?
- `pylint *.py` (as CI runs it) — 10.00/10, no new findings; `py_compile`
clean.
- Runs in CI in the k8s-delegation Docker Compose stack (real k3s cluster)
alongside the existing same-subject and negative-path tests:
```
tests-1 | ------------------------------------
tests-1 | Your code has been rated at 10.00/10
tests-1 |
tests-1 | Waiting for knox...
tests-1 | ============================= test session starts
==============================
tests-1 | platform linux
Issue Time Tracking
-------------------
Worklog Id: (was: 1044576)
Remaining Estimate: 0h
Time Spent: 10m
> k8s delegation E2E: policy-enforced SA actor-token delegation and headless
> SA-subject requested_subject exchange
> ----------------------------------------------------------------------------------------------------------------
>
> Key: KNOX-3493
> URL: https://issues.apache.org/jira/browse/KNOX-3493
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 3.1.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Critical
> Fix For: 3.1.0
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> *Description*
> Add the two token-exchange E2E scenarios that depend on delegation-policy
> enforcement in the exchange path - actor-token (on-behalf-of) delegation and
> headless (requested_subject) exchange. These cannot be tested against the
> currently-merged backend: TokenExchangeHandler builds a delegation Subject
> but performs no DelegationPolicyService.evaluate check, and there is no
> requested_subject/headless handling at all. This sub-task lands once that
> backend work merges, reusing the harness delivered by the sibling ticket.
> *In scope*
> Extend test_k8s_delegation.py (harness from the sibling ticket) with the
> delegation + headless scenarios below, including both the policy-allows (200)
> and policy-denies (400) cases.
> Seed delegation policies as part of test setup via the admin API (or the
> compose bootstrap) so the allow/deny paths are deterministic.
> *Out of scope*
> Harness, CA/issuer export, KNOXIDF_ADMIN topology, same-subject exchange, and
> negative-path tests — all delivered by the sibling ticket.
> The backend enforcement + requested_subject/headless implementation itself —
> tracked under the in-flight backend work (see Dependencies); this ticket is
> tests only.
> *Acceptance criteria*
> * (AC4) A delegation exchange with an SA actor_token + a Knox-user
> subject_token succeeds with HTTP 200 when a matching delegation policy
> exists, and is rejected with HTTP 400 when no policy matches.
> * (AC5) A headless exchange with an SA subject_token + requested_subject
> succeeds with HTTP 200 when policy allows headless delegation, and is
> rejected when it does not.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)