mirror of
https://github.com/vmware-tanzu/pinniped.git
synced 2026-09-19 14:34:27 +00:00
Merge branch 'dynamic_clients' into client-secret-api-noop
This commit is contained in:
@@ -666,6 +666,27 @@ func TestTokenEndpointTokenExchange(t *testing.T) { // tests for grant_type "urn
|
||||
wantStatus: http.StatusBadRequest,
|
||||
wantResponseBodyContains: "missing audience parameter",
|
||||
},
|
||||
{
|
||||
name: "bad requested audience when it looks like the name of an OIDCClient CR",
|
||||
authcodeExchange: doValidAuthCodeExchange,
|
||||
requestedAudience: "client.oauth.pinniped.dev-some-client-abc123",
|
||||
wantStatus: http.StatusBadRequest,
|
||||
wantResponseBodyContains: "requested audience cannot contain '.pinniped.dev'",
|
||||
},
|
||||
{
|
||||
name: "bad requested audience when it contains the substring .pinniped.dev because it is reserved for potential future usage",
|
||||
authcodeExchange: doValidAuthCodeExchange,
|
||||
requestedAudience: "something.pinniped.dev/some_aud",
|
||||
wantStatus: http.StatusBadRequest,
|
||||
wantResponseBodyContains: "requested audience cannot contain '.pinniped.dev'",
|
||||
},
|
||||
{
|
||||
name: "bad requested audience when it is the same name as the static public client pinniped-cli",
|
||||
authcodeExchange: doValidAuthCodeExchange,
|
||||
requestedAudience: "pinniped-cli",
|
||||
wantStatus: http.StatusBadRequest,
|
||||
wantResponseBodyContains: "requested audience cannot equal 'pinniped-cli'",
|
||||
},
|
||||
{
|
||||
name: "missing subject_token",
|
||||
authcodeExchange: doValidAuthCodeExchange,
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
// Copyright 2020 the Pinniped contributors. All Rights Reserved.
|
||||
// Copyright 2020-2022 the Pinniped contributors. All Rights Reserved.
|
||||
// SPDX-License-Identifier: Apache-2.0
|
||||
|
||||
package oidc
|
||||
@@ -6,6 +6,7 @@ package oidc
|
||||
import (
|
||||
"context"
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"github.com/coreos/go-oidc/v3/oidc"
|
||||
"github.com/ory/fosite"
|
||||
@@ -127,6 +128,24 @@ func (t *TokenExchangeHandler) validateParams(params url.Values) (*stsParams, er
|
||||
}
|
||||
}
|
||||
|
||||
// Validate that the requested audience is not one of the reserved strings. All possible requested audience strings
|
||||
// are subdivided into these classifications:
|
||||
// 1. pinniped-cli is reserved for the statically defined OAuth client, which is disallowed for this token exchange.
|
||||
// 2. client.oauth.pinniped.dev-* is reserved to be the names of user-defined dynamic OAuth clients, which is also
|
||||
// disallowed for this token exchange.
|
||||
// 3. Anything else matching *.pinniped.dev* is reserved for future use, in case we want to create more
|
||||
// buckets of names some day, e.g. something.pinniped.dev/*. These names are also disallowed for this
|
||||
// token exchange.
|
||||
// 4. Any other string is reserved to conceptually mean the name of a workload cluster (technically, it's the
|
||||
// configured audience of its Concierge JWTAuthenticator or other OIDC JWT validator). These are the only
|
||||
// allowed values for this token exchange.
|
||||
if strings.Contains(result.requestedAudience, ".pinniped.dev") {
|
||||
return nil, fosite.ErrInvalidRequest.WithHintf("requested audience cannot contain '.pinniped.dev'")
|
||||
}
|
||||
if result.requestedAudience == "pinniped-cli" {
|
||||
return nil, fosite.ErrInvalidRequest.WithHintf("requested audience cannot equal 'pinniped-cli'")
|
||||
}
|
||||
|
||||
return &result, nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user