feat(OBE-9898): always require a token, read site_version from claim#108
Draft
saurabhchauhan-s1 wants to merge 1 commit into
Draft
feat(OBE-9898): always require a token, read site_version from claim#108saurabhchauhan-s1 wants to merge 1 commit into
saurabhchauhan-s1 wants to merge 1 commit into
Conversation
The vector source's auth drops the require_token config knob: a valid bearer token is now always required, removing the legacy require_token=false bypass that accepted unauthenticated pushes. The site's version is read from the validated JWT's site_version claim (stamped by the manager auth-service, OBE-9896) and logged for telemetry / future per-version policy. - jwt_auth.rs: remove AuthConfig.require_token, default_require_token, Inner.require_token; authenticate() rejects a missing authorization header unconditionally; read SITE_VERSION_CLAIM from the decoded claims. - sources/vector/mod.rs: delete the legacy and now-redundant require_token tests, rename the kept ones to the unconditional behavior. - test_util/jwt_auth.rs: drop require_token from the shared build_auth helper. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The vector source's auth drops the require_token config knob: a valid bearer token is now always required, removing the legacy require_token=false bypass that accepted unauthenticated pushes. The site's version is read from the validated JWT's site_version claim (stamped by the manager auth-service, OBE-9896) and logged for telemetry / future per-version policy.
Summary
Vector configuration
How did you test this PR?
Change Type
Is this a breaking change?
Does this PR include user facing changes?
no-changeloglabel to this PR.References
Notes
@vectordotdev/vectorto reach out to us regarding this PR.pre-pushhook, please see this template.make fmtmake check-clippy(if there are failures it's possible some of them can be fixed withmake clippy-fix)make testgit merge origin masterandgit push.Cargo.lock), pleaserun
make build-licensesto regenerate the license inventory and commit the changes (if any). More details on the dd-rust-license-tool.