Record authenticated caller in the decision envelope.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 1m0s

FLEX-WP-0023-T04: provenance.caller is additive (mode required;
principal/audience/not_after when a token was reviewed). TokenReview
keeps the JWT exp. request_digest is unchanged because the caller is
not binding material.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
This commit is contained in:
tegwick 2026-09-14 04:44:07 +02:00
parent e62c0cfc36
commit ca070df32d
15 changed files with 344 additions and 35 deletions

View file

@ -235,10 +235,25 @@ func TestServeCallerAuthenticationBindsSystemToPrincipal(t *testing.T) {
if err != nil {
t.Fatal(err)
}
resp.Body.Close()
if resp.StatusCode != http.StatusOK {
resp.Body.Close()
t.Fatalf("bound caller status = %d; want 200", resp.StatusCode)
}
var envelope api.DecisionEnvelope
if err := json.NewDecoder(resp.Body).Decode(&envelope); err != nil {
resp.Body.Close()
t.Fatalf("decode decision: %v", err)
}
resp.Body.Close()
if envelope.Provenance.Caller == nil || envelope.Provenance.Caller.Mode != "enforce" {
t.Fatalf("caller = %+v; want enforce", envelope.Provenance.Caller)
}
if envelope.Provenance.Caller.Principal != "system:serviceaccount:ops-warden:ops-warden" {
t.Fatalf("principal = %q", envelope.Provenance.Caller.Principal)
}
if envelope.Provenance.Caller.Audience != "flex-auth" {
t.Fatalf("audience = %q", envelope.Provenance.Caller.Audience)
}
wrong, _ := callerauth.New(callerauth.ModeEnforce, fixedTokenReviewer{identity: callerauth.Identity{
Username: "system:serviceaccount:another:caller",