smolnar82 opened a new pull request, #1434:
URL: https://github.com/apache/knox/pull/1434

   [KNOX-3493](https://issues.apache.org/jira/browse/KNOX-3493) - k8s 
delegation E2E: policy-enforced SA actor-token delegation and headless 
requested_subject exchange
   
   ## What changes were proposed in this pull request?
   
   Extends the k8s ServiceAccount delegation harness (`test_k8s_delegation.py`) 
with the two policy-enforced RFC 8693 scenarios that were out of scope for the 
sibling harness ticket:
   
   - **AC4 — interactive delegation:** a k3s SA projected `actor_token` acting 
on behalf of a Knox-user `subject_token`. Succeeds (HTTP 200) under a matching 
`K8S_SA` delegation policy and is rejected (HTTP 400 `invalid_request`, 
"rejected by policy") when the policy authorizes a different subject.
   - **AC5 — headless delegation:** an SA `subject_token` + 
`requested_subject`. Succeeds when the policy sets `allowHeadlessExchange=true` 
and is rejected when it does not.
   
   Policies are seeded per-test through the KNOXIDF_ADMIN delegation-policy 
REST API via the existing `DelegationPolicyAdmin` helper; the SA actor key 
(`K8S_SA`, `<iss>:<ns>:<sa-name>`) is derived from the token itself, mirroring 
`ActorIdentity.fromJwt`. The exchange runs on the delegation-enabled 
`knoxidf-token-delegation-policy` topology; success paths assert the minted 
token records the impersonation (`sub` = impersonated user, nested `act.sub` = 
SA identity, requested resource as `aud`). Issuer registration and seeded 
policies are bracketed with `addCleanup`, so each test is self-contained 
regardless of run order. No existing test or `delegation_helpers.py` was 
modified.
   
   ## How was this patch tested?
   
   - `pylint *.py` (as CI runs it) — 10.00/10, no new findings; `py_compile` 
clean.
   - Runs in CI in the k8s-delegation Docker Compose stack (real k3s cluster) 
alongside the existing same-subject and negative-path tests:
   ```
   tests-1  | ------------------------------------
   tests-1  | Your code has been rated at 10.00/10
   tests-1  | 
   tests-1  | Waiting for knox...
   tests-1  | ============================= test session starts 
==============================
   tests-1  | platform linux -- Python 3.10.20, pytest-9.0.3, pluggy-1.6.0
   tests-1  | rootdir: /tests
   tests-1  | plugins: platformdirs-4.12.1
   tests-1  | collected 124 items
   tests-1  | 
   tests-1  | test_clientid_credentials.py .......                              
       [  5%]
   tests-1  | test_delegation.py .........                                      
       [ 12%]
   tests-1  | test_health.py .....                                              
       [ 16%]
   tests-1  | test_k8s_delegation.py .......                                    
       [ 22%]
   tests-1  | test_k8s_serviceaccount_validation.py ......                      
       [ 27%]
   tests-1  | test_knox_admin_path_traversal.py ...                             
       [ 29%]
   tests-1  | test_knox_auth_service_and_ldap.py ...                            
       [ 32%]
   tests-1  | test_knox_configs.py .                                            
       [ 33%]
   tests-1  | test_knox_ldap_cache.py ...                                       
       [ 35%]
   tests-1  | test_knox_ldap_injection.py .......                               
       [ 41%]
   tests-1  | test_knox_ldap_proxy_search.py .........                          
       [ 48%]
   tests-1  | test_knoxauth_preauth_and_paths.py ......                         
       [ 53%]
   tests-1  | test_knoxauth_token_forwarding.py ...........                     
       [ 62%]
   tests-1  | test_knoxidf.py .......                                           
       [ 67%]
   tests-1  | test_knoxsso_redirect.py .                                        
       [ 68%]
   tests-1  | test_knoxtoken_jwt.py ....................                        
       [ 84%]
   tests-1  | test_remote_auth.py ...                                           
       [ 87%]
   tests-1  | test_remoteauth_extauthz_additional_path.py ....                  
       [ 90%]
   tests-1  | test_token_exchange.py ............                               
       [100%]
   tests-1  | 
   tests-1  | =============================== warnings summary 
===============================
   ...
   tests-1  | -- Docs: 
https://docs.pytest.org/en/stable/how-to/capture-warnings.html
   tests-1  | ----------------- generated xml file: /tests/test-results.xml 
------------------
   tests-1  | ====================== 124 passed, 116 warnings in 31.39s 
======================
   
   ```
   
   ## Integration Tests
   
   This PR is integration tests only - the four scenarios are added to 
[`.github/workflows/tests/test_k8s_delegation.py`](.github/workflows/tests/test_k8s_delegation.py),
 reusing the compose overlay, CA/issuer export, and KNOXIDF_ADMIN topology 
delivered by the sibling harness ticket.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to