Project

General

Profile

Actions

Feature #17583

closed

Remote controller forwards trusted client aware calls on a federated scenario

Added by Lucas Di Pentima almost 3 years ago. Updated about 2 years ago.

Status:
Resolved
Priority:
Normal
Assigned To:
Category:
API
Target version:
Story points:
-
Release relationship:
Auto

Description

When a client makes for example a token list request to a remote controller using a federated token, the remote controller responds with a "Forbidden: this API client cannot manipulate other clients' access tokens." error message.

This most probably be due to the fact that federated tokens are cached on the remote controller's database but not linked to a trusted client.

The right solution would probably be to make controller forward those requests to the token issuing cluster so that from the client's perspective the operation is transparent.


Subtasks 2 (1 open1 closed)

Task #17872: Review 17583-federated-token-reqsResolvedLucas Di Pentima01/21/2022Actions
Task #17910: investigateNewPeter AmstutzActions

Related issues

Related to Arvados - Bug #17785: [controller/api] "Forbidden: this API client cannot manipulate other clients' access tokens." on federated login clusters (2.2.0 regression)ResolvedLucas Di Pentima11/23/2021Actions
Actions

Also available in: Atom PDF