mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* feat(auth): implement RFC 0011 Phase 2 workspace authorization Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): address PR review feedback on workspace authorization - Docker e2e: add --health-port and switch readiness probe from `openshell status` to `curl /healthz`, fixing a false-positive readiness check in OIDC mode where the CLI exited 0 without actually contacting the gateway - ListWorkspaces: move membership filtering from post-query N+1 lookups into a SQL EXISTS subquery so pagination applies to the visible set, not the global ordering. Add generic list_with_membership to the persistence layer. - Descriptor validator: reject role/scope fields on unauthenticated and sandbox auth modes, and allow-list workspace_role as user/admin and global_role as platform_admin to catch typos at startup Signed-off-by: Derek Carr <decarr@redhat.com> * fix(server): use authed request in delete telemetry test The workspace authorization added by the Phase 2 auth changes requires a Principal on every delete request. The delete-telemetry test was still using a bare Request::new, so extract_principal failed before the handler could acquire the delete gate, causing a 5-second timeout flake. Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): address gator review findings for workspace authorization - Inject unauthenticated-local-dev principal in no-auth gateway mode so handlers that call extract_principal() always find one. - Cap label-selector membership query at MAX_PAGE_SIZE instead of u32::MAX to bound the in-memory read. - Authorize workspace membership before resolving workspace existence in all sandbox RPCs to prevent workspace-name enumeration by non-members. - Remove dead_code allow on AuthorizedWorkspace.workspace now that callers use the normalized name from the authz result. Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): close workspace-name oracle and label-selector truncation Swap authorize-before-resolve ordering in 27 handlers across provider.rs, service.rs, policy.rs, and workspace.rs to prevent CWE-203 workspace-name enumeration by non-members. Add combined membership+label SQL query (list_with_membership_and_selector) to both persistence backends so ListWorkspaces with label selectors no longer silently drops results beyond the first page of membership matches. Signed-off-by: Derek Carr <decarr@redhat.com> * test(auth): add non-member rejection and membership+label persistence tests Add comprehensive test coverage for workspace authorization changes: - Non-member rejection tests across all 44 workspace-scoped handlers (sandbox, provider, service, policy, workspace, inference) verifying PERMISSION_DENIED is returned instead of NOT_FOUND to prevent CWE-203 workspace-name oracle - Persistence test for list_with_membership_and_selector verifying SQL-level membership EXISTS + label filtering, multiple predicates, no-match cases, and pagination Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): format merged import line in sandbox tests Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): address gator re-review findings on workspace authorization - Fix TUI unconditionally setting providers_v2_enabled after provider refresh; read the actual gateway setting via GetGatewayConfig at startup instead - Fix SQLite json_extract with dotted label keys (e.g. example.com/env) by quoting the key in the JSON path - Add authed_request wrappers to upstream OCI identity tests that were missing a principal after rebase - Add test proving GetGatewayConfig is accessible without Platform Admin - Add test for dotted/prefixed Kubernetes-style label key filtering Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): address second gator re-review findings - Loosen GetGatewayConfig from platform_admin to scope-only so workspace users can discover providers_v2_enabled during sandbox creation with inferred-provider commands; update proto descriptor, descriptor validation, and RFC 0011 access table - Add validate_label_selector to handle_list_workspaces and escape single quotes in SQLite json_extract interpolation (CWE-89 defense-in-depth) - Re-fetch providers_v2_enabled after TUI gateway switch so the new gateway's capability is reflected - Add e2e test for workspace user with inferred-provider command - Add persistence test for adversarial label keys with SQL injection attempts - Add handler test for invalid label selector rejection in ListWorkspaces Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): address third gator review findings - Cap label selector pairs at 64 (CWE-400) to bound SQLite dynamic SQL - Add SCOPE_ONLY_METHODS allowlist for scope-without-role RPCs (CWE-863) - Normalize ID-based data-plane handlers to return NOT_FOUND for unauthorized sandboxes, closing the cross-workspace oracle (CWE-203) - Fix TUI provider profile cache lookup key mismatch for legacy providers with empty profile_workspace - Add whoami to CLI skill reference command tree - Update TUI skill doc with workspace, provider, and settings coverage - Document scope/workspace orthogonality on GetGatewayConfig proto Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): extend CWE-203 normalization to policy.rs sandbox handlers GetSandboxConfig and GetSandboxLogs in policy.rs had the same fetch-before-authorize pattern that leaked cross-workspace sandbox existence. Promote fetch_and_authorize_sandbox to pub(super) and use it from both sandbox.rs and policy.rs handlers. Signed-off-by: Derek Carr <decarr@redhat.com> * test(auth): update assertions for CWE-203 sandbox ID normalization Cross-workspace sandbox access via ID-based handlers now returns NOT_FOUND instead of PERMISSION_DENIED to prevent existence inference. Update the unit test and OIDC e2e assertion to match. Signed-off-by: Derek Carr <decarr@redhat.com> * fix(auth): narrow CWE-203 error mapping and correct whoami output formats Only remap PERMISSION_DENIED to NOT_FOUND in fetch_and_authorize_sandbox and RevokeSshSession, letting INTERNAL and UNAUTHENTICATED propagate as-is. Fix whoami --output format values in cli-reference.md to match the actual CLI (table/json/yaml, not text/json). Signed-off-by: Derek Carr <decarr@redhat.com> * fix(ci): share network namespace with Keycloak in containerized CI In GitHub Actions job containers, Docker port publishing lands on the host, not inside the job container. Detect this environment and attach Keycloak to the job container's network namespace instead, with hardened defaults (cap-drop ALL, no-new-privileges, loopback-only listener). Signed-off-by: Derek Carr <decarr@redhat.com> --------- Signed-off-by: Derek Carr <decarr@redhat.com>
164 lines
5.0 KiB
Python
164 lines
5.0 KiB
Python
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
"""Shared helpers for OIDC e2e tests.
|
|
|
|
Provides Keycloak token acquisition, gRPC channel setup, and JWT utilities.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import base64
|
|
import json
|
|
import os
|
|
import urllib.parse
|
|
import urllib.request
|
|
from pathlib import Path
|
|
|
|
import grpc
|
|
|
|
from openshell._proto import openshell_pb2_grpc
|
|
|
|
KEYCLOAK_REALM = "openshell"
|
|
|
|
|
|
def _xdg_config_home() -> Path:
|
|
return Path(os.environ.get("XDG_CONFIG_HOME", Path.home() / ".config"))
|
|
|
|
|
|
def keycloak_url() -> str:
|
|
"""Derive the Keycloak URL from the gateway's stored OIDC issuer.
|
|
|
|
The server validates the issuer claim in JWTs, so the token must be
|
|
requested from the same base URL the server was configured with
|
|
(typically the host IP, not localhost).
|
|
"""
|
|
if url := os.environ.get("OPENSHELL_KEYCLOAK_URL"):
|
|
return url
|
|
if issuer := os.environ.get("OPENSHELL_E2E_OIDC_ISSUER"):
|
|
idx = issuer.find("/realms/")
|
|
if idx > 0:
|
|
return issuer[:idx]
|
|
cluster_name = os.environ.get("OPENSHELL_GATEWAY", "openshell")
|
|
metadata_path = (
|
|
_xdg_config_home() / "openshell" / "gateways" / cluster_name / "metadata.json"
|
|
)
|
|
if metadata_path.exists():
|
|
metadata = json.loads(metadata_path.read_text())
|
|
issuer = metadata.get("oidc_issuer", "")
|
|
if issuer:
|
|
idx = issuer.find("/realms/")
|
|
if idx > 0:
|
|
return issuer[:idx]
|
|
return "http://localhost:8180"
|
|
|
|
|
|
TOKEN_ENDPOINT = (
|
|
f"{keycloak_url()}/realms/{KEYCLOAK_REALM}/protocol/openid-connect/token"
|
|
)
|
|
|
|
|
|
def _gateway_endpoint() -> tuple[str, bool]:
|
|
"""Read the active gateway endpoint from metadata."""
|
|
if endpoint := os.environ.get("OPENSHELL_E2E_OIDC_GATEWAY_ENDPOINT"):
|
|
return endpoint, endpoint.startswith("https://")
|
|
cluster_name = os.environ.get("OPENSHELL_GATEWAY", "openshell")
|
|
metadata_path = (
|
|
_xdg_config_home() / "openshell" / "gateways" / cluster_name / "metadata.json"
|
|
)
|
|
metadata = json.loads(metadata_path.read_text())
|
|
endpoint = metadata["gateway_endpoint"]
|
|
is_tls = endpoint.startswith("https://")
|
|
return endpoint, is_tls
|
|
|
|
|
|
def _mtls_dir() -> Path:
|
|
cluster_name = os.environ.get("OPENSHELL_GATEWAY", "openshell")
|
|
return _xdg_config_home() / "openshell" / "gateways" / cluster_name / "mtls"
|
|
|
|
|
|
def _token_request(data: dict[str, str]) -> str:
|
|
"""POST to the Keycloak token endpoint and return the access token."""
|
|
encoded = urllib.parse.urlencode(data).encode()
|
|
req = urllib.request.Request(TOKEN_ENDPOINT, data=encoded)
|
|
with urllib.request.urlopen(req, timeout=10) as resp:
|
|
body = json.loads(resp.read())
|
|
return body["access_token"]
|
|
|
|
|
|
def get_token(
|
|
username: str,
|
|
password: str,
|
|
*,
|
|
client_id: str = "openshell-cli",
|
|
scopes: str | None = None,
|
|
) -> str:
|
|
"""Get an access token from Keycloak via password grant."""
|
|
data = {
|
|
"grant_type": "password",
|
|
"client_id": client_id,
|
|
"username": username,
|
|
"password": password,
|
|
}
|
|
if scopes:
|
|
data["scope"] = scopes
|
|
return _token_request(data)
|
|
|
|
|
|
def get_ci_token(
|
|
*,
|
|
client_id: str = "openshell-ci",
|
|
client_secret: str = "ci-test-secret",
|
|
) -> str:
|
|
"""Get an access token via client credentials grant."""
|
|
return _token_request(
|
|
{
|
|
"grant_type": "client_credentials",
|
|
"client_id": client_id,
|
|
"client_secret": client_secret,
|
|
}
|
|
)
|
|
|
|
|
|
def grpc_channel() -> grpc.Channel:
|
|
"""Create a gRPC channel to the gateway over its configured TLS transport."""
|
|
endpoint, is_tls = _gateway_endpoint()
|
|
parsed = urllib.parse.urlparse(endpoint)
|
|
host = parsed.hostname or "127.0.0.1"
|
|
port = parsed.port or (443 if is_tls else 80)
|
|
target = f"{host}:{port}"
|
|
|
|
if is_tls:
|
|
if ca_path := os.environ.get("OPENSHELL_E2E_GATEWAY_CA_CERT"):
|
|
creds = grpc.ssl_channel_credentials(
|
|
root_certificates=Path(ca_path).read_bytes()
|
|
)
|
|
else:
|
|
mtls = _mtls_dir()
|
|
creds = grpc.ssl_channel_credentials(
|
|
root_certificates=(mtls / "ca.crt").read_bytes(),
|
|
private_key=(mtls / "tls.key").read_bytes(),
|
|
certificate_chain=(mtls / "tls.crt").read_bytes(),
|
|
)
|
|
return grpc.secure_channel(target, creds)
|
|
return grpc.insecure_channel(target)
|
|
|
|
|
|
def stub_with_token(
|
|
token: str,
|
|
) -> tuple[openshell_pb2_grpc.OpenShellStub, list[tuple[str, str]]]:
|
|
"""Create a gRPC stub that injects a Bearer token."""
|
|
channel = grpc_channel()
|
|
return openshell_pb2_grpc.OpenShellStub(channel), [
|
|
("authorization", f"Bearer {token}")
|
|
]
|
|
|
|
|
|
def extract_sub(token: str) -> str:
|
|
"""Extract the 'sub' claim from a JWT access token."""
|
|
payload = token.split(".")[1]
|
|
padded = payload + "=" * (4 - len(payload) % 4)
|
|
decoded = base64.urlsafe_b64decode(padded)
|
|
claims = json.loads(decoded)
|
|
return claims["sub"]
|