Reject service-identity fields a browser client silently ignores
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 34s

serviceSubject and roles are read only on the client_credentials path. On a
browser client they are accepted and then ignored, since subject and roles come
from the directory user -- so a registration that looks effective fails later as
a downstream rejection rather than as a registration defect. tokenLifetime was
already rejected this way, so the rule existed and was incomplete.

Nothing in dev-config, the example fixture or the live deployment sets either
field on a browser client, checked against all three rather than assumed, so this
breaks no existing configuration.

tenant is deliberately excluded, and a test pins that: a browser client may
declare one, and humanTenant resolves it against the directory, refusing issuance
when they disagree (KEY-WP-0013-T05). An earlier version of this change rejected
tenant too and would have made that feature unusable. It started from T05's
blocker paragraph, which was accurate when written and already fixed by the time
this task began -- blocker prose ages faster than the code it describes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
This commit is contained in:
tegwick 2026-09-09 14:42:26 +02:00
parent 329e48f64a
commit 74b35b6107
3 changed files with 90 additions and 18 deletions

View file

@ -551,7 +551,6 @@ func TestValidate_ServiceIdentityFieldsRejectedOnBrowserClients(t *testing.T) {
mutate func(*config.ClientConfig)
want string
}{
"tenant": {func(c *config.ClientConfig) { c.Tenant = "tenant:platform" }, "tenant"},
"serviceSubject": {func(c *config.ClientConfig) { c.ServiceSubject = "service:approver" }, "serviceSubject"},
"roles": {func(c *config.ClientConfig) { c.Roles = []string{"approver"} }, "roles"},
}
@ -580,13 +579,22 @@ func TestValidate_ServiceIdentityFieldsRejectedOnBrowserClients(t *testing.T) {
cfg := validConfig(writeTempFile(t, "key"))
client := browserClient()
client.GrantTypes = nil
client.Tenant = "tenant:platform"
if errs := config.ValidateConfig(cfg); len(errs) != 0 {
t.Fatalf("baseline config invalid: %v", errs)
}
client.ServiceSubject = "service:approver"
cfg.Clients = append(cfg.Clients, client)
if errs := config.ValidateConfig(cfg); len(errs) == 0 {
t.Fatal("expected tenant to be rejected on an implicit authorization-code client")
t.Fatal("expected serviceSubject to be rejected on an implicit authorization-code client")
}
})
// A browser client MAY declare a tenant: humanTenant resolves it against the
// directory (KEY-WP-0013-T05). Rejecting it here would break that.
t.Run("tenant is allowed on a browser client", func(t *testing.T) {
cfg := validConfig(writeTempFile(t, "key"))
client := browserClient()
client.Tenant = "tenant:platform"
cfg.Clients = append(cfg.Clients, client)
if errs := config.ValidateConfig(cfg); len(errs) != 0 {
t.Fatalf("browser client tenant rejected: %v", errs)
}
})