🛂(backend) add audience to jwt

Add audience to the jwt, scoping the token to it
prevents an admin JWT issued for another backend
service from being replayed against y-provider.
This commit is contained in:
Anthony LC
2026-09-01 15:16:22 +02:00
parent b3f88f00ac
commit 6dab2c174c
5 changed files with 41 additions and 6 deletions
@@ -13,6 +13,11 @@ from core.services.jwt_services import JWTService
logger = logging.getLogger(__name__)
# Audience of the admin token y-provider expects. Scoping the token to it
# prevents an admin JWT issued for another backend service from being
# replayed against y-provider.
Y_CONVERTER_AUDIENCE = "y-converter"
class ConversionError(Exception):
"""Base exception for conversion-related errors."""
@@ -110,7 +115,8 @@ class YdocConverter:
@property
def auth_header(self):
"""Build microservice authentication header."""
return f"Bearer {JWTService().get_admin_token()}"
token = JWTService().get_admin_token({"aud": Y_CONVERTER_AUDIENCE})
return f"Bearer {token}"
def _request(self, url, data, content_type, accept):
"""Make a request to the Y-Provider API."""
@@ -27,14 +27,17 @@ def jwt_settings(settings):
def test_auth_header():
"""The auth header carries an admin JWT signed with the configured key."""
"""The auth header carries an admin JWT scoped to the y-converter audience."""
converter = YdocConverter()
scheme, token = converter.auth_header.split(" ")
assert scheme == "Bearer"
payload = jwt.decode(token, PUBLIC_KEY, algorithms=["RS256"])
payload = jwt.decode(
token, PUBLIC_KEY, algorithms=["RS256"], audience="y-converter"
)
assert payload["admin"] is True
assert payload["aud"] == "y-converter"
def test_convert_empty_text():