Skip to content

Align security routing specs with fail-closed identity verification - #175

Merged
woksin merged 1 commit into
mainfrom
fix/security-routing-fixtures
Oct 2, 2026
Merged

woksin merged 1 commit into
mainfrom
fix/security-routing-fixtures

Conversation

@woksin

@woksin woksin commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The service-routing security specs opt their routing-only services out of identity resolution, so routing and service-authorization assertions run independently of the fail-closed identity-verification default. (#176)

@woksin woksin self-assigned this Oct 1, 2026
@woksin

woksin commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Tracked by #174.

Root cause: #169 introduced ServiceRoutingHarness without an identity-resolution opt-out after #164 made IdentityVerification default to Required. RecordingBackend answers /.cratis/me with {}, not an explicit positive verification verdict, so authenticated routing requests receive 403 before reaching the routing behavior under test. The routing-only services now set ResolveIdentityDetails=false; product defaults, Required-verification specs, claim requirements and all assertions are unchanged.

The baseline at e5e0f84 reproduced 18 failures and 269 passes. No management-listener failure occurred in the baseline or fixed runs; its fixture already selects an OS-assigned port using TcpListener on port zero, so it was left unchanged.

Local checks passed through pi-phase with --timeout 300 --queue-timeout 600:

  • dotnet build Source/AuthProxy.Security.Specs/AuthProxy.Security.Specs.csproj --configuration Release -warnaserror (the first edited build caught a comment-placement StyleCop error; corrected and retried once successfully).
  • dotnet test Source/AuthProxy.Security.Specs/AuthProxy.Security.Specs.csproj --configuration Release --no-build: 287 passed.
  • dotnet build --configuration Release -warnaserror and dotnet build --configuration Debug -warnaserror: zero warnings/errors.
  • dotnet test Source/AuthProxy.Specs/AuthProxy.Specs.csproj --configuration Release --no-build: 2432 passed; same command with Debug: 2432 passed.
  • dotnet test Source/Aspire.Specs/Aspire.Specs.csproj --configuration Release --no-build: 77 passed; same command with Debug: 77 passed.
  • dotnet test Source/AuthProxy.Security.Specs/AuthProxy.Security.Specs.csproj --configuration Debug --no-build: 287 passed.
  • git diff --check passed; repository analyzers/style checks ran in both solution builds. No standalone frontend lint/format gate is defined for this change.

Frontend and .NET dependency audits were not run locally; GitHub's Security workflow will run them. Docker publishing is not applicable to this no-release PR. The full review workflow remains for the orchestrator before any merge. Do not merge as part of this task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant