Repository navigation
Forward a per-audience access token for the signed-in user to backends - #171
Conversation
An OIDC provider can now authenticate AuthProxy to its token endpoint with a private_key_jwt client assertion signed by a certificate (file, certificate store or Azure Key Vault), or with a federated token (workload identity token file or Azure managed identity), instead of a client secret. The credential loaders come from Microsoft.Identity.Web; ClientSecret stays the default and configuring both fails at startup.
A service can declare AccessToken scopes (or an RFC 8707 resource). AuthProxy keeps the refresh token issued at sign-in server-side, keyed by an unguessable reference inside the encrypted session cookie, redeems it at the provider's token endpoint for the service's audience (client secret or client assertion), caches the access token per session and audience until shortly before expiry, and forwards it as Authorization: Bearer on requests to the service's backend. Requests that cannot get a token are refused with 401.
|
Notes for reviewers (not part of the release note): Stacked on #167 (base Design decisions (conservative choices; flag any you want changed)
Local gate (mirrors CI): This is security-sensitive and needs a cross-provider review before merge. |
…ser-access-tokens
…ser-access-tokens # Conflicts: # Source/AuthProxy/ReverseProxy/MicroserviceReverseProxyConfigProvider.cs
…ser-access-tokens # Conflicts: # Source/AuthProxy/ReverseProxy/MicroserviceReverseProxyConfigProvider.cs # Source/AuthProxy/ReverseProxy/ReverseProxyExtensions.cs
…ser-access-tokens
…als' into feature/155-forward-user-access-tokens
|
Addressed both confirmed findings: merged current origin/main first, then incorporated the current #167 credential branch without replacing its signing, certificate reload, sovereign-cloud or password fixes. #167 is still open, so its changes remain in the main-based diff; the release note describes only #155. Token policy now comes from the selected cluster's immutable metadata. Backend cluster and destination IDs are versioned by address and full token policy. Added unit coverage for policy-only/address-only reloads and immutable policies, plus a running-YARP regression that blocks token acquisition, changes both backend and audience, and checks which origin receives each token. Targeted local checks via pi-phase:
No whole-solution local gates were run, per the owner instruction. The PR's CI remains the full Debug/Release and complete-spec gate; it was not watched or awaited. No merge or label changes were made. |
|
Fixed the confirmed routing regressions in e081b20. Backend cluster IDs keep the existing Added security regressions with real generated proxy routes: root and service claim requirements permit the authorized cookie caller and forward its bearer token; machine tokens are accepted on their own service and rejected on another token-forwarding backend selected by host or prefix, including conflicting header/query selection. The existing in-flight reload regression still passes. Fixtures explicitly declare identity verification mode without weakening assertions. Local checks used pi-phase as requested:
Whole-solution builds, the remaining spec suites, Docker/publish checks and dependency audits were intentionally left to the PR's CI per the owner's targeted-only local check decision. CI was not watched or awaited. No merge or label changes. The current diff against origin/main still includes the OIDC credential feature from #149, and #167 is open. The release note now includes that feature rather than relying on merge order. The unreleased token-binding guarantee is in Added, not Security. |
|
Merged current origin/main (including #167) and fixed both confirmed reports of the policy/destination reload race. Backend cluster metadata now carries the versioned destination binding. Cookie-session token forwarding checks both AvailableDestinations and AllDestinations against it before token acquisition and returns 503 for a mismatch or missing/unavailable binding. Service resolution and machine-caller behavior remain unchanged. Added deterministic unit specs that freeze the new-policy/old-destination snapshot between YARP's separate publications, plus coverage for independently stale destination lists, missing metadata, unavailable destinations and the provider's metadata binding. The regression constructs that intermediate snapshot directly; it does not instrument YARP's internal configuration manager. Local checks:
Whole-solution Debug/Release builds, remaining spec projects and Docker checks are left to this PR's CI as requested; CI was not watched. Release notes were checked against the current diff, updated to describe 503 during reload mismatches, and the already-merged #149 bullet was removed. One push: 6271850. No merge or label changes. |
Added
AccessToken.ScopesorAccessToken.Resource. Tokens remain server-side, and cached and renewed per session and audience. Backend requests receiveAuthorization: Bearer, or401when no token can be obtained. Requests that capture mismatched token policies and destinations during a reload receive503before a token is obtained; retry after the reload completes. Frontend routes, anonymous paths and machine callers with their own bearer token remain unchanged. See Forwarding the user's access token. (Forward a per-audience access token for the signed-in user to backends #155)Session.SlidingExpirationis enabled, remove them on logout, and back off for 30 seconds per audience afterinvalid_grant. (Forward a per-audience access token for the signed-in user to backends #155)