mirror of
https://github.com/suitenumerique/docs.git
synced 2026-09-30 13:35:10 +02:00
🛂(backend) add audience to jwt
Add audience to the jwt, scoping the token to it prevents an admin JWT issued for another backend service from being replayed against y-provider.
This commit is contained in:
@@ -13,6 +13,11 @@ from core.services.jwt_services import JWTService
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
# Audience of the admin token y-provider expects. Scoping the token to it
|
||||
# prevents an admin JWT issued for another backend service from being
|
||||
# replayed against y-provider.
|
||||
Y_CONVERTER_AUDIENCE = "y-converter"
|
||||
|
||||
|
||||
class ConversionError(Exception):
|
||||
"""Base exception for conversion-related errors."""
|
||||
@@ -110,7 +115,8 @@ class YdocConverter:
|
||||
@property
|
||||
def auth_header(self):
|
||||
"""Build microservice authentication header."""
|
||||
return f"Bearer {JWTService().get_admin_token()}"
|
||||
token = JWTService().get_admin_token({"aud": Y_CONVERTER_AUDIENCE})
|
||||
return f"Bearer {token}"
|
||||
|
||||
def _request(self, url, data, content_type, accept):
|
||||
"""Make a request to the Y-Provider API."""
|
||||
|
||||
@@ -27,14 +27,17 @@ def jwt_settings(settings):
|
||||
|
||||
|
||||
def test_auth_header():
|
||||
"""The auth header carries an admin JWT signed with the configured key."""
|
||||
"""The auth header carries an admin JWT scoped to the y-converter audience."""
|
||||
converter = YdocConverter()
|
||||
|
||||
scheme, token = converter.auth_header.split(" ")
|
||||
|
||||
assert scheme == "Bearer"
|
||||
payload = jwt.decode(token, PUBLIC_KEY, algorithms=["RS256"])
|
||||
payload = jwt.decode(
|
||||
token, PUBLIC_KEY, algorithms=["RS256"], audience="y-converter"
|
||||
)
|
||||
assert payload["admin"] is True
|
||||
assert payload["aud"] == "y-converter"
|
||||
|
||||
|
||||
def test_convert_empty_text():
|
||||
|
||||
Reference in New Issue
Block a user