Conversation
…ter in spire test
- require an audience on every --jwt-auth-provider when --jwt-svid-auth is set (startup error) and a non-empty `aud` claim on SVIDs; fail startup when no provider is configured; wizard asks for the missing audience - validate_jwt_svid: async, refreshes the JWKS once and retries, accepts only spiffe:// subjects - advertise "SPIFFE" in /ui/auth_method, keep the JWT method gated as before; UI shows a gateway notice when SPIFFE is the only method - expose the production JWT validation as validate_signed_token and cover it with real signature/audience/expiry unit tests - ckms login spire: accept bare absolute socket paths, reject relative ones - document /ui/login_svid in openapi.yaml, add jwt_svid_auth to the config templates and regenerated docs - mise: spire-jwt-svid validates for real on Linux (HTTPS JWKS, negative checks), macOS falls back to an insecure build; fail-fast auth-verifier build, cleanup - docs/ADR/changelog aligned with the implemented behaviour (mTLS CN precedence, gateway shared-identity caveat)
- /ui/login_svid: renew the session ID before storing user_id to prevent session fixation. - Require a non-empty trust domain in SPIFFE subjects (reject bare `spiffe://` and `spiffe:///path`). - handle_jwt: log the actual rejection reason instead of always "no email in JWT" (e.g. missing `aud` on an SVID). - pre-commit: drop duplicate `ui/src/i18n/locales/fr/` typos exclude. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Nw1fHzCJJQUGNM3URi77gK
`clippy::indexing_slicing` rejects `claims["aud"] = ...` under `cargo clippy --tests -D warnings`; use a small `set_claim` helper. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Nw1fHzCJJQUGNM3URi77gK
Manuthor
had a problem deploying
to
xks-remote-approval
September 29, 2026 20:52 — with
GitHub Actions
Failure
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebased-on-review version of Cosmian#1206: the original PR commits plus fixes for the review findings, based on the current
Cosmian/kmsdevelop.Summary (from Cosmian#1206)
--jwt-svid-auth/KMS_JWT_SVID_AUTH/[idp_auth] jwt_svid_auth: a validated JWT with noemailclaim is authenticated via itssubwhen it is a SPIFFE ID (AuthMethod::JwtSvid). Every provider must set an audience; SVIDs without a non-emptyaudare rejected.POST /ui/login_svidfor gateway/BFF Web UI sessions,SPIFFEadvertised in/ui/auth_method.ckms login spirefetches a JWT-SVID from the local SPIRE Agent Workload API.test:spire-jwt-svidE2E suite, shared.mise/lib/spire_test.shhelpers, docs and ADR.Review fixes
/ui/login_svidnow callssession.renew()before storinguser_id.spiffe:///spiffe:///pathare rejected); tests added.handle_jwtlogs the actual rejection reason instead of always "no email in JWT" (e.g. SVID missingaud).real_validationtests usedclaims["…"] = …, which failsclippy::indexing_slicingunder--tests -D warnings; replaced with aset_claimhelper..pre-commit-config.yaml: removed duplicateui/src/i18n/locales/fr/typos exclude.Not changed (author's call):
/ui/login_svidreturns 500 when the feature is disabled (consistent withlogin_as; docs/tests expect it);.mise/tasks/test/README.md(1.7k-line generic test doc) could be split into its own PR.Test plan
cargo test -p cosmian_kms_server --lib --features non-fips -- middlewares::jwt routes::ui_auth jwt_svid auth_wizard— 41 passed (incl. real ES256 signature/issuer/audience/expiry validation)cargo clippy -p cosmian_kms_server -p cosmian_kms_cli_actions --lib --tests --features non-fips -- -D warnings— cleanmise run test:spire-jwt-svid(needs Docker + SPIRE; not run here)🤖 Generated with Claude Code
https://claude.ai/code/session_01Nw1fHzCJJQUGNM3URi77gK
Generated by Claude Code