Align approval registrations to the tenant:platform decision
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 33s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 33s
Operator decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6 accepts tenant:platform as the platform management tenant for the Glas approval chain, requiring exact spelling across the approval store, the service-client JWT claim and the lifecycle CheckRequest. Changes the tenant field on secrets-engine-approval and approval-engine-operator only, in the registration fixture and the provisioning packet. Unrelated clients and the human directory default keep tenant:coulomb, and no audience, scope, subject, role, lifetime or MFA grant changes. Adds issuance evidence that the approval shape emits tenant:platform exactly and never an alias the caller requests, that the OpenBao client gains no cross-tenant reach, and a fixture guard pinning every reviewed client's tenant. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P Assistant: claude-code Assistant-Model: opus Assistant-Process: 713576@bnt-lap001 Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
This commit is contained in:
parent
519e4d8ef1
commit
7a6666d1f9
8 changed files with 199 additions and 28 deletions
|
|
@ -36,3 +36,36 @@ func TestServiceRegistrationAudienceAndScopeIsolation(t *testing.T) {
|
|||
t.Fatal("OpenBao audience default changed")
|
||||
}
|
||||
}
|
||||
|
||||
// The Glas approval chain requires exact tenant spelling across the approval
|
||||
// store, these JWT claims and the lifecycle CheckRequest (decision
|
||||
// 5ed3fb35-eca9-413a-82b9-95171ba85bf6). Aliases to "platform" or
|
||||
// "tenant:coulomb" are rejected, and unrelated clients keep their own tenant.
|
||||
func TestServiceRegistrationTenantsAreExactPerDecision(t *testing.T) {
|
||||
cfg, err := config.Load("../../../config/service-clients.example.yaml")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
want := map[string]string{
|
||||
"secrets-engine-approval": "tenant:platform",
|
||||
"approval-engine-operator": "tenant:platform",
|
||||
"codex-railiance-platform": "tenant:coulomb",
|
||||
"secrets-engine-openbao": "tenant:coulomb",
|
||||
}
|
||||
seen := map[string]bool{}
|
||||
for _, c := range cfg.Clients {
|
||||
expected, ok := want[c.ClientID]
|
||||
if !ok {
|
||||
t.Fatalf("unreviewed client %s has tenant %q", c.ClientID, c.Tenant)
|
||||
}
|
||||
if c.Tenant != expected {
|
||||
t.Fatalf("%s: tenant %q, want exactly %q", c.ClientID, c.Tenant, expected)
|
||||
}
|
||||
seen[c.ClientID] = true
|
||||
}
|
||||
for id := range want {
|
||||
if !seen[id] {
|
||||
t.Fatalf("missing reviewed registration %s", id)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue