Skip to content

ateapi: make the actor JWT issuer configurable and add typ to the header - #1834

Merged
Taahir Ahmed (ahmedtd) merged 2 commits into
agent-substrate:mainfrom
thompsonmax:actor-jwt-issuer-flag
Sep 25, 2026
Merged

Taahir Ahmed (ahmedtd) merged 2 commits into
agent-substrate:mainfrom
thompsonmax:actor-jwt-issuer-flag

Conversation

@thompsonmax

@thompsonmax Max Thompson (thompsonmax) commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Part of #1756.

  • Adds --actor-jwt-issuer. Unset, it defaults to https://idp.<namespace>.svc, the Service ate-idp-server will serve discovery from. Before this, iss was hardcoded to https://api.ate-system.svc, which points at ateapi's gRPC port.
  • Adds oidcdiscovery.ParseIssuer, which requires a canonical https URL with no query, fragment, or user info and strips trailing slashes. ate-idp-server will use it too, so both emit the same bytes.
  • Actor JWT headers now include typ: JWT.
  • Drops the actorIdentityJWTIssuer plumbing into RPCService, unused since Identity: Move actor JWT/cert minting into the main API #1315.

The default iss changes, but MintActorJWT has no production caller yet.

Testing: new unit tests for the parser, the default, the header, and flag resolution. TestMintActorJWT_Success now checks typ, iss, and sub. It needs Docker, so it hasn't run locally.

Comment thread internal/oidcdiscovery/issuer.go Outdated
Comment thread internal/oidcdiscovery/issuer.go Outdated
Actor JWTs carried the hardcoded issuer https://api.ate-system.svc. That
URL points at ateapi's gRPC port, which serves no discovery document, so
nothing outside ateapi could verify the tokens.

Add --actor-jwt-issuer. When it is unset, the issuer is
https://idp.<namespace>.svc, the Service that will serve the discovery
document and key set. Relying parties compare issuers byte for byte, so
the value must be a canonical https URL with no query, fragment, or user
info. Trailing slashes are stripped.

Tokens now carry typ: JWT in the JOSE header, as RFC 8725 section 3.11
recommends.

RPCService's actorIdentityJWTIssuer field had no reader once minting
moved into the control API, so its constructor slot now carries the actor
JWT issuer.
Replace ParseIssuer with ValidateIssuer, which checks the issuer without
rewriting it. ateapi no longer strips trailing slashes or rejects URLs
that url.Parse would re-encode.

Relying parties compare iss byte for byte against the issuer they
registered, so the token has to carry the operator's exact string.
OpenID Connect Discovery already has relying parties drop a trailing
slash before appending /.well-known/openid-configuration.
@ahmedtd
Taahir Ahmed (ahmedtd) added this pull request to the merge queue Sep 25, 2026
Merged via the queue into agent-substrate:main with commit d3a556a Sep 25, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/api-machinery area/identity kind/feature An enhancement / feature request or implementation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants