Skip to content

refactor(sts)!: drop RoleConfig.allow_missing_exp_from - #163

Draft
alukach wants to merge 1 commit into
mainfrom
sts/drop-allow-missing-exp-from
Draft

alukach wants to merge 1 commit into
mainfrom
sts/drop-allow-missing-exp-from

Conversation

@alukach

@alukach alukach commented Oct 6, 2026

Copy link
Copy Markdown
Member

What I'm changing

#146 added RoleConfig.allow_missing_exp_from so that a host minting its own long-lived tokens with no exp could exempt its issuer from the new expiry requirement (the caveat in #143). The only host that planned to do that was Source Cooperative, for proxy-signed API keys (#147). It has since moved to opaque sck_ keys that the proxy resolves by hash lookup before the STS verifier ever sees a token (source-cooperative/data.source.coop#234, source-cooperative/data.source.coop#235), so #147 was closed and nothing sets the field to anything but [].

An exemption nobody uses is only a way to misconfigure a role into accepting replayable tokens, so this removes it: every role now requires exp, from every issuer. If a host does need it later, it comes back with that host's use case to shape it.

The rest of #146 (fail-closed audiences and subjects, the typ check, the unresolved-template error, success logging) is unaffected.

How I did it

  • crates/core/src/types.rs — drop the field.
  • crates/sts/src/jwks.rs — a missing exp is always an error; the test is now exp_is_required and loses its exemption half.
  • crates/static-config/src/lib.rs — drop the field from the test fixture.
  • crates/sts/README.md, docs/configuration/roles.md, docs/auth/proxy-auth.md — drop it from the docs.

Breaking

Struct-literal RoleConfig constructors must drop the field. The one known downstream is source-cooperative/data.source.coop src/sts.rs, which sets allow_missing_exp_from: vec![] and needs that line deleted on its next bump. TOML/JSON configs that still carry the key keep loading, since RoleConfig doesn't deny unknown fields.

Test plan

  • cargo check --locked
  • cargo clippy -- -D warnings
  • cargo test — all suites pass
  • pre-commit hooks, including cargo check for wasm

🤖 Generated with Claude Code

Every role now requires `exp` on the tokens it exchanges, with no per-issuer exemption. The exemption existed for a host that mints long-lived tokens with no expiry and tracks their validity itself; the one host that planned to (Source Cooperative's API keys) moved to opaque keys resolved outside the STS verifier, so no issuer needs it and an unused exemption is only a way to misconfigure a role into accepting replayable tokens.

BREAKING CHANGE: `RoleConfig` loses `allow_missing_exp_from`. Struct-literal constructors must drop the field. Config files that still set it keep loading (the key is ignored), but tokens without `exp` are now rejected for every issuer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @alukach's task in 9s —— View job


✅ No blocking issues — safe to merge.

The diff removes RoleConfig.allow_missing_exp_from and makes a missing exp an unconditional error in validate_claims (crates/sts/src/jwks.rs). I read the diff only and did not build or run the tests. A grep for allow_missing_exp finds no remaining references outside CHANGELOG.md, which is generated release history and should stay as is.

The change fails closed. serde ignores unknown fields on RoleConfig, so old configs that still carry the key keep loading, and the key then has no effect. Tokens without exp are rejected for every issuer. That matches the PR description.

Simplify (ponytail)

  • crates/sts/src/jwks.rs:~245: the None => { return Err(..) } arm could be folded into a let Some(exp) = ... else { return Err(..) }, which would drop one nesting level. This is cosmetic, so skip it if you prefer the current shape.

💰 Estimated review cost: $0.11 · 0m08s · 4 turns

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

📖 Docs preview deployed to https://multistore-docs-pr-163.development-seed.workers.dev

  • Date: 2026-10-06T00:03:04Z
  • Commit: 999f506

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🚀 Latest commit deployed to https://multistore-proxy-pr-163.development-seed.workers.dev

  • Date: 2026-10-06T00:03:04Z
  • Commit: 999f506

This branch was successfully deployed

1 active deployment
preview — d74d139f Deployed Oct 6, 2026 by alukach via Deploy & Test / Deploy #478
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant