Feature #17583

Remote controller forwards trusted client aware calls on a federated scenario

Added by Lucas Di Pentima 9 months ago. Updated 4 days ago.

Status:
In Progress
Priority:
Normal
Assigned To:
Category:
API
Target version:
Start date:
01/21/2022
Due date:
% Done:

0%

Estimated time:
(Total: 0.00 h)
Story points:
-

Description

When a client makes for example a token list request to a remote controller using a federated token, the remote controller responds with a "Forbidden: this API client cannot manipulate other clients' access tokens." error message.

This most probably be due to the fact that federated tokens are cached on the remote controller's database but not linked to a trusted client.

The right solution would probably be to make controller forward those requests to the token issuing cluster so that from the client's perspective the operation is transparent.


Subtasks

Task #17872: Review 17583-federated-token-reqsIn ProgressPeter Amstutz

Task #17910: investigateNewPeter Amstutz


Related issues

Related to Arvados - Bug #17785: [controller/api] "Forbidden: this API client cannot manipulate other clients' access tokens." on federated login clusters (2.2.0 regression)Resolved11/23/2021

History

#1 Updated by Ward Vandewege 7 months ago

  • Related to Bug #17785: [controller/api] "Forbidden: this API client cannot manipulate other clients' access tokens." on federated login clusters (2.2.0 regression) added

#2 Updated by Peter Amstutz 7 months ago

  • Target version changed from To Be Groomed to 2021-07-21 sprint

#3 Updated by Peter Amstutz 7 months ago

  • Assigned To set to Peter Amstutz

#4 Updated by Peter Amstutz 6 months ago

  • Target version changed from 2021-07-21 sprint to 2021-08-04 sprint

#5 Updated by Peter Amstutz 6 months ago

  • Target version changed from 2021-08-04 sprint to 2021-08-18 sprint

#6 Updated by Peter Amstutz 6 months ago

  • Target version changed from 2021-08-18 sprint to 2021-09-01 sprint

#7 Updated by Peter Amstutz 6 months ago

  • Target version changed from 2021-09-01 sprint to 2021-09-15 sprint

#8 Updated by Peter Amstutz 5 months ago

  • Assigned To deleted (Peter Amstutz)

#9 Updated by Peter Amstutz 5 months ago

  • Assigned To set to Lucas Di Pentima

#10 Updated by Lucas Di Pentima 4 months ago

  • Target version changed from 2021-09-15 sprint to 2021-09-29 sprint

#11 Updated by Peter Amstutz 4 months ago

  • Target version changed from 2021-09-29 sprint to 2021-10-13 sprint

#12 Updated by Lucas Di Pentima 3 months ago

  • Target version changed from 2021-10-13 sprint to 2021-10-27 sprint

#13 Updated by Lucas Di Pentima 3 months ago

  • Target version changed from 2021-10-27 sprint to 2021-11-10 sprint

#14 Updated by Peter Amstutz 3 months ago

  • Target version changed from 2021-11-10 sprint to 2021-11-24 sprint

#15 Updated by Lucas Di Pentima 2 months ago

  • Target version changed from 2021-11-24 sprint to 2021-12-08 sprint

#16 Updated by Peter Amstutz about 2 months ago

  • Target version changed from 2021-12-08 sprint to 2022-01-05 sprint

#17 Updated by Peter Amstutz about 2 months ago

  • Target version changed from 2022-01-05 sprint to 2022-01-19 sprint

#18 Updated by Lucas Di Pentima 6 days ago

  • Target version changed from 2022-01-19 sprint to 2022-02-02 sprint

#19 Updated by Lucas Di Pentima 4 days ago

  • Status changed from New to In Progress

#20 Updated by Lucas Di Pentima 4 days ago

Updates at 3c18a9d - branch 17583-federated-token-reqs
Test run: https://ci.arvados.org/job/developer-run-tests/2887/

  • Expands test to expose a pending bug.
  • Forwards list requests.
  • Adds code to honor the bypass_federation as done with the users.

Also available in: Atom PDF