test(auth): enable mTLS and actor_token WIF integration tests by default - #14554
macastelaz wants to merge 36 commits into
Conversation
…401 recovery - Pin mTLS HttpTransportFactory across multi-step STS and IAM token exchanges so both requests use the exact same certificate snapshot within a single refresh cycle. - Add 401 Unauthorized recovery with automatic certificate reload from X509Provider and single-retry coordination in IdentityPoolCredentials and ImpersonatedCredentials. - Preserve custom non-default HttpTransportFactory instances when X509Provider is configured. - Add comprehensive unit tests across IdentityPoolCredentialsTest, ImpersonatedCredentialsTest, and OAuth2UtilsTest.
…dentials and address review findings - Explicitly scope inner sourceCredentials to CLOUD_PLATFORM_SCOPE in ExternalAccountCredentials.buildImpersonatedCredentials and ImpersonatedCredentials.refreshAccessToken so STS issues tokens authorized to call IAM generateAccessToken even when downstream target scopes are configured via createScoped. - Ensure public no-arg ImpersonatedCredentials.refreshAccessToken delegates without overriding source credential transport settings. - Preserve custom actorTokenSupplier in IdentityPoolCredentials.Builder copy constructor when credentialSource is present. - Ensure HTTP response is closed in a finally block in ImpersonatedCredentials.refreshAccessToken. - Attach initial 401 exception as suppressed when the 401 retry attempt fails in IdentityPoolCredentials.refreshWithRetry. - Add unit tests in IdentityPoolCredentialsTest and ImpersonatedCredentialsTest covering scoped impersonation, custom actorTokenSupplier preservation, and retry exception chaining.
…in IdentityPoolCredentials
…ss and FILE cert pinning
…InternalExtensionOnly
…ration tests - Add MtlsPipelineLocalTest providing hermetic in-process socket tests over JDK HttpsServer with client certificate authentication (peer cert verification, 401 retry with cert rotation, concurrent refreshes, atomic token read, IAM impersonation mTLS transport pinning, and 401 retry with fresh cert). - Add ITWorkloadIdentityFederationTest extensions for certificate-bound workload + actor token JSON config and programmatic mTLS token suppliers covering both direct STS and Service Account Impersonation. - Fix OAuthException to safely handle null HTTP error response content.
…integration tests
…tlsPipelineLocalTest, and ITWorkloadIdentityFederationTest
…th mTLS impersonation, and retry torn cert rotations
…als and retry bare IOExceptions on split cert writes
… and single cert read on impersonated refresh
…als and CertificateIdentityPoolSubjectTokenSupplier
…LS pinning - Replace the ThreadLocal 401 signal with CachedStsTokenRejectedException. - Only clear the cached STS token on IAM failure when this refresh used it and it is still the cached token. - Scope the external source before taking the pinned impersonation path, and clear any access token copied by createScoped(). - Simplify isRetryableTransportException and drop redundant retry checks. - Pass the cycle transport factory through for Aws/Pluggable impersonation. - Javadoc and comment clarifications. - Add tests for concurrent STS cache handling, standalone ImpersonatedCredentials 401 retries, transport factory upgrade, source scoping, isInvalidGrantException, and Aws/Pluggable cycle factories.
… cert-bound-oauth-integration-tests
…CATE_CONFIG is unset
…on and local pipeline tests
… no usable description
- Clear the copied access token before building the impersonation source credentials, so a rebuilt source (e.g. after deserialization) mints a fresh STS token instead of sending the cached service account token to IAM. - Pin serialVersionUID for CertificateIdentityPoolSubjectTokenSupplier and OAuthException to their released computed values so previously serialized instances still load.
… cert-bound-oauth-integration-tests # Conflicts: # google-auth-library-java/oauth2_http/java/com/google/auth/oauth2/OAuthException.java # google-auth-library-java/oauth2_http/javatests/com/google/auth/oauth2/OAuthExceptionTest.java
There was a problem hiding this comment.
Code Review
This pull request introduces robust support for per-cycle mTLS transport pinning, certificate rotation, and automatic retry recovery across both STS and IAM token exchanges in Google Workload Identity Federation. Key changes include extracting leaf certificates directly from pinned KeyStores, caching intermediate STS tokens in ImpersonatedCredentials to prevent redundant exchanges, and implementing a retry mechanism in IdentityPoolCredentials that reloads rotated certificates upon encountering 401 Unauthorized or 400 invalid_grant errors. Additionally, helper utilities for comparing KeyStore entries and parsing structured OAuth exceptions were added, along with a comprehensive hermetic integration test suite (MtlsPipelineLocalTest) to validate the entire mTLS pipeline. There are no review comments, so I have no feedback to provide.
Summary
Stacked on top of #14220 (
cert-bound-oauth-integration-tests).Enables the 4 mTLS +
actor_tokenWorkload Identity Federation integration tests inITWorkloadIdentityFederationTestto run by default in CI without requiringGOOGLE_API_CERTIFICATE_CONFIGor external Secret Manager secrets:testresources/mtls/certificate_config.json(test_cert.pem/test_key.pem) whenGOOGLE_API_CERTIFICATE_CONFIGis unset, removing theassumeTrueskip.cnf.x5t#S256andmay_act: Targetsoidc-jwt-1(OIDC_JWT_AUDIENCE) and uses theGOOGLE_APPLICATION_CREDENTIALSservice account private key (whose public key is registered inoidc-jwt-1'sjwksJson) to sign OIDC JWTs containing RFC 8705 certificate thumbprint binding (cnf.x5t#S256) and delegation (may_act) claims.