Skip to content

ateapi: fail cleanly on a malformed actor JWT signing pool - #601

Open
Mesut Oezdil (mesutoezdil) wants to merge 2 commits into
agent-substrate:mainfrom
mesutoezdil:fix/session-jwt-pool-panics
Open

ateapi: fail cleanly on a malformed actor JWT signing pool#601
Mesut Oezdil (mesutoezdil) wants to merge 2 commits into
agent-substrate:mainfrom
mesutoezdil:fix/session-jwt-pool-panics

Conversation

@mesutoezdil

@mesutoezdil Mesut Oezdil (mesutoezdil) commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

MintJWT indexes Authorities[0] from the actor JWT signing pool file, and actoridjwt.Sign type-asserts the signing key without checking it, so a pool file carrying no authorities (which localjwtauthority.Unmarshal accepts without error) or an algorithm that does not match its key panics instead of returning an error. Nothing in the server installs a panic-recovery interceptor, so that configuration error takes down ate-api-server on the first MintJWT call, and MintCert already guards the same situation for its own pool. This adds the missing checks plus the first tests for both packages, which also pin the behavior of the paths that already worked.

MintJWT reads the signing pool file on every call and indexes Authorities[0]
directly. localjwtauthority.Unmarshal reports no error for JSON that carries no
authorities, so an empty or incompletely written pool file reaches that index
and panics. sessionidjwt.Sign then type-asserts the signing key without
checking, so a pool entry whose algorithm does not match its key type panics as
well. Neither is recoverable: nothing in the server installs a panic-recovery
interceptor, so a configuration error in the pool file takes down
ate-api-server on the first MintJWT call rather than returning an error to the
caller.

Check the pool for authorities before selecting one, and check each key type
assertion in Sign. MintCert already guards an empty session CA pool the same
way; this brings the JWT path in line with it.

The signing-authority selection moves into a helper so it can be tested without
standing up an OIDC issuer to satisfy the client-JWT verification that precedes
it. Both packages had no tests; the ones added here also pin the existing
behavior of the working paths.
…panics

# Conflicts:
#	cmd/ateapi/internal/actoridentity/actoridentity.go
#	cmd/ateapi/internal/actoridentity/sessionidentity_test.go
#	cmd/ateapi/internal/actoridjwt/sessionidjwt_test.go
@mesutoezdil Mesut Oezdil (mesutoezdil) changed the title ateapi: fail cleanly on a malformed session JWT signing pool ateapi: fail cleanly on a malformed actor JWT signing pool Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant