镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

test(auth): enable mTLS and actor_token WIF integration tests by default - #14554

Open
macastelaz wants to merge 36 commits into
googleapis:oauth2-bound-tokensfrom
macastelaz:enable-mtls-wif-integration-tests
Open

macastelaz wants to merge 36 commits into
googleapis:oauth2-bound-tokensfrom
macastelaz:enable-mtls-wif-integration-tests

Conversation

@macastelaz

Copy link
Copy Markdown
Contributor

Summary

Stacked on top of #14220 (cert-bound-oauth-integration-tests).

Enables the 4 mTLS + actor_token Workload Identity Federation integration tests in ITWorkloadIdentityFederationTest to run by default in CI without requiring GOOGLE_API_CERTIFICATE_CONFIG or external Secret Manager secrets:

  1. Default mTLS Certificate Config Fallback: Falls back to the checked-in testresources/mtls/certificate_config.json (test_cert.pem / test_key.pem) when GOOGLE_API_CERTIFICATE_CONFIG is unset, removing the assumeTrue skip.
  2. Signed OIDC JWTs with cnf.x5t#S256 and may_act: Targets oidc-jwt-1 (OIDC_JWT_AUDIENCE) and uses the GOOGLE_APPLICATION_CREDENTIALS service account private key (whose public key is registered in oidc-jwt-1's jwksJson) to sign OIDC JWTs containing RFC 8705 certificate thumbprint binding (cnf.x5t#S256) and delegation (may_act) claims.

…401 recovery

- Pin mTLS HttpTransportFactory across multi-step STS and IAM token exchanges so both requests use the exact same certificate snapshot within a single refresh cycle.
- Add 401 Unauthorized recovery with automatic certificate reload from X509Provider and single-retry coordination in IdentityPoolCredentials and ImpersonatedCredentials.
- Preserve custom non-default HttpTransportFactory instances when X509Provider is configured.
- Add comprehensive unit tests across IdentityPoolCredentialsTest, ImpersonatedCredentialsTest, and OAuth2UtilsTest.
…dentials and address review findings

- Explicitly scope inner sourceCredentials to CLOUD_PLATFORM_SCOPE in ExternalAccountCredentials.buildImpersonatedCredentials and ImpersonatedCredentials.refreshAccessToken so STS issues tokens authorized to call IAM generateAccessToken even when downstream target scopes are configured via createScoped.
- Ensure public no-arg ImpersonatedCredentials.refreshAccessToken delegates without overriding source credential transport settings.
- Preserve custom actorTokenSupplier in IdentityPoolCredentials.Builder copy constructor when credentialSource is present.
- Ensure HTTP response is closed in a finally block in ImpersonatedCredentials.refreshAccessToken.
- Attach initial 401 exception as suppressed when the 401 retry attempt fails in IdentityPoolCredentials.refreshWithRetry.
- Add unit tests in IdentityPoolCredentialsTest and ImpersonatedCredentialsTest covering scoped impersonation, custom actorTokenSupplier preservation, and retry exception chaining.
…ration tests

- Add MtlsPipelineLocalTest providing hermetic in-process socket tests over JDK HttpsServer with client certificate authentication (peer cert verification, 401 retry with cert rotation, concurrent refreshes, atomic token read, IAM impersonation mTLS transport pinning, and 401 retry with fresh cert).
- Add ITWorkloadIdentityFederationTest extensions for certificate-bound workload + actor token JSON config and programmatic mTLS token suppliers covering both direct STS and Service Account Impersonation.
- Fix OAuthException to safely handle null HTTP error response content.
…tlsPipelineLocalTest, and ITWorkloadIdentityFederationTest
…th mTLS impersonation, and retry torn cert rotations
…als and retry bare IOExceptions on split cert writes
… and single cert read on impersonated refresh
…als and CertificateIdentityPoolSubjectTokenSupplier
…LS pinning

- Replace the ThreadLocal 401 signal with CachedStsTokenRejectedException.
- Only clear the cached STS token on IAM failure when this refresh used it and
  it is still the cached token.
- Scope the external source before taking the pinned impersonation path, and
  clear any access token copied by createScoped().
- Simplify isRetryableTransportException and drop redundant retry checks.
- Pass the cycle transport factory through for Aws/Pluggable impersonation.
- Javadoc and comment clarifications.
- Add tests for concurrent STS cache handling, standalone
  ImpersonatedCredentials 401 retries, transport factory upgrade, source
  scoping, isInvalidGrantException, and Aws/Pluggable cycle factories.
- Clear the copied access token before building the impersonation source credentials, so a rebuilt source (e.g. after deserialization) mints a fresh STS token instead of sending the cached service account token to IAM.
- Pin serialVersionUID for CertificateIdentityPoolSubjectTokenSupplier and OAuthException to their released computed values so previously serialized instances still load.
… cert-bound-oauth-integration-tests

# Conflicts:
#	google-auth-library-java/oauth2_http/java/com/google/auth/oauth2/OAuthException.java
#	google-auth-library-java/oauth2_http/javatests/com/google/auth/oauth2/OAuthExceptionTest.java
@macastelaz
macastelaz requested review from a team as code owners September 30, 2026 02:33

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces robust support for per-cycle mTLS transport pinning, certificate rotation, and automatic retry recovery across both STS and IAM token exchanges in Google Workload Identity Federation. Key changes include extracting leaf certificates directly from pinned KeyStores, caching intermediate STS tokens in ImpersonatedCredentials to prevent redundant exchanges, and implementing a retry mechanism in IdentityPoolCredentials that reloads rotated certificates upon encountering 401 Unauthorized or 400 invalid_grant errors. Additionally, helper utilities for comparing KeyStore entries and parsing structured OAuth exceptions were added, along with a comprehensive hermetic integration test suite (MtlsPipelineLocalTest) to validate the entire mTLS pipeline. There are no review comments, so I have no feedback to provide.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant