Prepare tenant-zero OpenBao roles and review platform essentials
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
4f20e755c4
commit
5781d34b3b
10 changed files with 179 additions and 14 deletions
30
tests/test_secrets_engine_jwt_contract.py
Normal file
30
tests/test_secrets_engine_jwt_contract.py
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
"""Source safety bounds; live JWT verification remains attended acceptance."""
|
||||
import json
|
||||
import re
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
ROOT = Path(__file__).resolve().parents[1]
|
||||
|
||||
class ServiceJWTContract(unittest.TestCase):
|
||||
def test_platform_identity_is_exact_and_cannot_be_an_applier(self):
|
||||
role = json.loads((ROOT / "openbao/auth/secrets-engine-jwt-role.json").read_text())
|
||||
self.assertEqual(role["bound_audiences"], ["secrets-engine-openbao"])
|
||||
self.assertEqual(role["bound_subject"], "service:secrets-engine")
|
||||
self.assertEqual(role["bound_claims"], dict(principal_type="service", tenant="tenant:platform", roles="secrets-engine", scope="openbao:login"))
|
||||
self.assertEqual(role["bound_claims_type"], "string")
|
||||
self.assertEqual(role["token_policies"], ["secrets-engine-login-self"])
|
||||
self.assertTrue(role["token_no_default_policy"])
|
||||
self.assertFalse(role["verbose_oidc_logging"])
|
||||
self.assertEqual(role["token_type"], "service")
|
||||
self.assertEqual(role["token_num_uses"], 8)
|
||||
for key in ("token_ttl", "token_max_ttl", "token_explicit_max_ttl"):
|
||||
self.assertEqual(role[key], "5m")
|
||||
self.assertNotIn("token_period", role)
|
||||
|
||||
def test_only_self_endpoints_and_pinned_signature_verifier(self):
|
||||
policy = (ROOT / "openbao/policies/secrets-engine-login-self.hcl").read_text()
|
||||
grants = re.findall(r'path "([^"]+)"\s*{\s*capabilities = \["([^"]+)"\]', policy)
|
||||
self.assertEqual(grants, [("auth/token/lookup-self", "read"), ("sys/capabilities-self", "update"), ("auth/token/revoke-self", "update")])
|
||||
self.assertNotIn("*", policy)
|
||||
config = json.loads((ROOT / "openbao/auth/keycape-services-config.json").read_text())
|
||||
self.assertEqual(config, dict(jwks_url="https://kc.coulomb.social/jwks", bound_issuer="https://kc.coulomb.social", jwt_supported_algs=["RS256"]))
|
||||
Loading…
Add table
Add a link
Reference in a new issue