Repository navigation
ateapi: make the actor JWT issuer configurable and add typ to the header - #1834
Merged
Taahir Ahmed (ahmedtd) merged 2 commits intoSep 25, 2026
Merged
Taahir Ahmed (ahmedtd) merged 2 commits into
Taahir Ahmed (ahmedtd) merged 2 commits into
Conversation
Max Thompson (thompsonmax)
requested review from
Shruti Nair (SHRUTI6991) and
Taahir Ahmed (ahmedtd)
September 23, 2026 21:34
Max Thompson (thompsonmax)
marked this pull request as ready for review
September 23, 2026 21:34
Taahir Ahmed (ahmedtd)
approved these changes
Sep 25, 2026
Actor JWTs carried the hardcoded issuer https://api.ate-system.svc. That URL points at ateapi's gRPC port, which serves no discovery document, so nothing outside ateapi could verify the tokens. Add --actor-jwt-issuer. When it is unset, the issuer is https://idp.<namespace>.svc, the Service that will serve the discovery document and key set. Relying parties compare issuers byte for byte, so the value must be a canonical https URL with no query, fragment, or user info. Trailing slashes are stripped. Tokens now carry typ: JWT in the JOSE header, as RFC 8725 section 3.11 recommends. RPCService's actorIdentityJWTIssuer field had no reader once minting moved into the control API, so its constructor slot now carries the actor JWT issuer.
Replace ParseIssuer with ValidateIssuer, which checks the issuer without rewriting it. ateapi no longer strips trailing slashes or rejects URLs that url.Parse would re-encode. Relying parties compare iss byte for byte against the issuer they registered, so the token has to carry the operator's exact string. OpenID Connect Discovery already has relying parties drop a trailing slash before appending /.well-known/openid-configuration.
Max Thompson (thompsonmax)
force-pushed
the
actor-jwt-issuer-flag
branch
from
September 25, 2026 17:58
52d6aee to
83fbf53
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #1756.
--actor-jwt-issuer. Unset, it defaults tohttps://idp.<namespace>.svc, the Service ate-idp-server will serve discovery from. Before this,isswas hardcoded tohttps://api.ate-system.svc, which points at ateapi's gRPC port.oidcdiscovery.ParseIssuer, which requires a canonical https URL with no query, fragment, or user info and strips trailing slashes. ate-idp-server will use it too, so both emit the same bytes.typ: JWT.actorIdentityJWTIssuerplumbing intoRPCService, unused since Identity: Move actor JWT/cert minting into the main API #1315.The default
isschanges, butMintActorJWThas no production caller yet.Testing: new unit tests for the parser, the default, the header, and flag resolution.
TestMintActorJWT_Successnow checkstyp,iss, andsub. It needs Docker, so it hasn't run locally.