Repository navigation
Conversation
Every role now requires `exp` on the tokens it exchanges, with no per-issuer exemption. The exemption existed for a host that mints long-lived tokens with no expiry and tracks their validity itself; the one host that planned to (Source Cooperative's API keys) moved to opaque keys resolved outside the STS verifier, so no issuer needs it and an unused exemption is only a way to misconfigure a role into accepting replayable tokens. BREAKING CHANGE: `RoleConfig` loses `allow_missing_exp_from`. Struct-literal constructors must drop the field. Config files that still set it keep loading (the key is ignored), but tokens without `exp` are now rejected for every issuer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @alukach's task in 9s —— View job ✅ No blocking issues — safe to merge. The diff removes The change fails closed. Simplify (ponytail)
💰 Estimated review cost: $0.11 · 0m08s · 4 turns |
|
📖 Docs preview deployed to https://multistore-docs-pr-163.development-seed.workers.dev
|
|
🚀 Latest commit deployed to https://multistore-proxy-pr-163.development-seed.workers.dev
|
What I'm changing
#146 added
RoleConfig.allow_missing_exp_fromso that a host minting its own long-lived tokens with noexpcould exempt its issuer from the new expiry requirement (the caveat in #143). The only host that planned to do that was Source Cooperative, for proxy-signed API keys (#147). It has since moved to opaquesck_keys that the proxy resolves by hash lookup before the STS verifier ever sees a token (source-cooperative/data.source.coop#234, source-cooperative/data.source.coop#235), so #147 was closed and nothing sets the field to anything but[].An exemption nobody uses is only a way to misconfigure a role into accepting replayable tokens, so this removes it: every role now requires
exp, from every issuer. If a host does need it later, it comes back with that host's use case to shape it.The rest of #146 (fail-closed audiences and subjects, the
typcheck, the unresolved-template error, success logging) is unaffected.How I did it
crates/core/src/types.rs— drop the field.crates/sts/src/jwks.rs— a missingexpis always an error; the test is nowexp_is_requiredand loses its exemption half.crates/static-config/src/lib.rs— drop the field from the test fixture.crates/sts/README.md,docs/configuration/roles.md,docs/auth/proxy-auth.md— drop it from the docs.Breaking
Struct-literal
RoleConfigconstructors must drop the field. The one known downstream is source-cooperative/data.source.coopsrc/sts.rs, which setsallow_missing_exp_from: vec![]and needs that line deleted on its next bump. TOML/JSON configs that still carry the key keep loading, sinceRoleConfigdoesn't deny unknown fields.Test plan
cargo check --lockedcargo clippy -- -D warningscargo test— all suites passcargo checkfor wasm🤖 Generated with Claude Code