[ 
https://issues.apache.org/jira/browse/KNOX-3493?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sandor Molnar updated KNOX-3493:
--------------------------------
    Description: 
*Description*

Add the two token-exchange E2E scenarios that depend on delegation-policy 
enforcement in the exchange path - actor-token (on-behalf-of) delegation and 
headless (requested_subject) exchange. These cannot be tested against the 
currently-merged backend: TokenExchangeHandler builds a delegation Subject but 
performs no DelegationPolicyService.evaluate check, and there is no 
requested_subject/headless handling at all. This sub-task lands once that 
backend work merges, reusing the harness delivered by the sibling ticket.

*In scope*

Extend test_k8s_delegation.py (harness from the sibling ticket) with the 
delegation + headless scenarios below, including both the policy-allows (200) 
and policy-denies (400) cases.

Seed delegation policies as part of test setup via the admin API (or the 
compose bootstrap) so the allow/deny paths are deterministic.

*Out of scope*

Harness, CA/issuer export, KNOXIDF_ADMIN topology, same-subject exchange, and 
negative-path tests — all delivered by the sibling ticket.

The backend enforcement + requested_subject/headless implementation itself — 
tracked under the in-flight backend work (see Dependencies); this ticket is 
tests only.

*Acceptance criteria*
 * (AC4) A delegation exchange with an SA actor_token + a Knox-user 
subject_token succeeds with HTTP 200 when a matching delegation policy exists, 
and is rejected with HTTP 400 when no policy matches.
 * (AC5) A headless exchange with an SA subject_token + requested_subject 
succeeds with HTTP 200 when policy allows headless delegation, and is rejected 
when it does not.

  was:
*Description*

Add the two token-exchange E2E scenarios that depend on delegation-policy 
enforcement in the exchange path - actor-token (on-behalf-of) delegation and 
headless (requested_subject) exchange. These cannot be tested against the 
currently-merged backend: TokenExchangeHandler builds a delegation Subject but 
performs no DelegationPolicyService.evaluate check, and there is no 
requested_subject/headless handling at all. This sub-task lands once that 
backend work merges, reusing the harness delivered by the sibling ticket.

*In scope*

Extend test_k8s_delegation.py (harness from the sibling ticket) with the 
delegation + headless scenarios below, including both the policy-allows (200) 
and policy-denies (403) cases.

Seed delegation policies as part of test setup via the admin API (or the 
compose bootstrap) so the allow/deny paths are deterministic.

*Out of scope*

Harness, CA/issuer export, KNOXIDF_ADMIN topology, same-subject exchange, and 
negative-path tests — all delivered by the sibling ticket.

The backend enforcement + requested_subject/headless implementation itself — 
tracked under the in-flight backend work (see Dependencies); this ticket is 
tests only.

*Acceptance criteria*
 * (AC4) A delegation exchange with an SA actor_token + a Knox-user 
subject_token succeeds with HTTP 200 when a matching delegation policy exists, 
and is rejected with HTTP 400 when no policy matches.
 * (AC5) A headless exchange with an SA subject_token + requested_subject 
succeeds with HTTP 200 when policy allows headless delegation, and is rejected 
when it does not.


> k8s delegation E2E: policy-enforced SA actor-token delegation and headless 
> SA-subject requested_subject exchange
> ----------------------------------------------------------------------------------------------------------------
>
>                 Key: KNOX-3493
>                 URL: https://issues.apache.org/jira/browse/KNOX-3493
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>    Affects Versions: 3.1.0
>            Reporter: Sandor Molnar
>            Assignee: Sandor Molnar
>            Priority: Critical
>             Fix For: 3.1.0
>
>
> *Description*
> Add the two token-exchange E2E scenarios that depend on delegation-policy 
> enforcement in the exchange path - actor-token (on-behalf-of) delegation and 
> headless (requested_subject) exchange. These cannot be tested against the 
> currently-merged backend: TokenExchangeHandler builds a delegation Subject 
> but performs no DelegationPolicyService.evaluate check, and there is no 
> requested_subject/headless handling at all. This sub-task lands once that 
> backend work merges, reusing the harness delivered by the sibling ticket.
> *In scope*
> Extend test_k8s_delegation.py (harness from the sibling ticket) with the 
> delegation + headless scenarios below, including both the policy-allows (200) 
> and policy-denies (400) cases.
> Seed delegation policies as part of test setup via the admin API (or the 
> compose bootstrap) so the allow/deny paths are deterministic.
> *Out of scope*
> Harness, CA/issuer export, KNOXIDF_ADMIN topology, same-subject exchange, and 
> negative-path tests — all delivered by the sibling ticket.
> The backend enforcement + requested_subject/headless implementation itself — 
> tracked under the in-flight backend work (see Dependencies); this ticket is 
> tests only.
> *Acceptance criteria*
>  * (AC4) A delegation exchange with an SA actor_token + a Knox-user 
> subject_token succeeds with HTTP 200 when a matching delegation policy 
> exists, and is rejected with HTTP 400 when no policy matches.
>  * (AC5) A headless exchange with an SA subject_token + requested_subject 
> succeeds with HTTP 200 when policy allows headless delegation, and is 
> rejected when it does not.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to