Skip to content

feature: new filter tokenExchange() based on rfc-8693 - #4316

Merged
szuecs merged 15 commits into
masterfrom
feature/token-exchange-rfc-8693
Oct 5, 2026
Merged

szuecs merged 15 commits into
masterfrom
feature/token-exchange-rfc-8693

Conversation

@szuecs

@szuecs szuecs commented Oct 2, 2026

Copy link
Copy Markdown
Member

@szuecs szuecs added the minor no risk changes, for example new filters label Oct 2, 2026
@github-actions github-actions Bot added enhancement feature definition documentation labels Oct 2, 2026
Comment thread filters/auth/token_exchange.go Outdated
Comment thread filters/auth/token_exchange.go
Comment thread docs/reference/filters.md
Comment thread filters/auth/token_exchange.go
Comment thread skipper.go Outdated
Comment thread config/config.go
szuecs added 4 commits October 5, 2026 10:17
ref https://www.rfc-editor.org/rfc/rfc8693

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
@szuecs
szuecs force-pushed the feature/token-exchange-rfc-8693 branch from 15748e8 to b059824 Compare October 5, 2026 08:18
@zalando-robot

Copy link
Copy Markdown

Docker image "registry-write.opensource.zalan.do/teapot/skipper:b0598248e00f58ad4a8355f2d4f753fe3e0230b7" is not based on an approved base image. Any production deployment relying on this image will be blocked.

To create a compliant Docker image of your application, you must reference an allowed Docker image as its base image in your Dockerfile. This base image must come from the Zalando Container Registry namespace library and use a recommended version as listed in the documentation.

szuecs added 6 commits October 5, 2026 10:41
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
… bytes.NewReader without converting

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
…ese mandatory

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
…ed to support by Auth Server, instead of form values which is only set to MAY for auth servers.

ref #4316 (comment)

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Comment thread filters/auth/token_exchange_test.go Outdated
szuecs added 2 commits October 5, 2026 16:28
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
…hServer so AuthServer would not be compliant to the RFC.

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
Comment thread skipper.go Outdated
for _, p := range o.CredentialsPaths {
if err := sp.Add(p); err != nil {
log.Errorf("Failed to add credentials file: %s: %v", p, err)
log.Fatalf("Failed to add credentials file: %s: %v", p, err)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 agree, it's better to fail here.

@a4180p a4180p Oct 5, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

but… tests are failing exactly because of this one :/
we miss something in tests setup, probably

there are several tests like that

CredentialsPaths: []string{"/does-not-exist"},

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, then I will create a separate PR for this kind of change, thanks for finding this. On my machine I had plugins failures for whatever reason and make clean did not fix these...

Comment thread filters/auth/token_exchange.go Outdated
Comment thread filters/auth/token_exchange.go Outdated
Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
…m-urlencoded. Tests failed because Go test was not reading the for value if the content-type is not correctly set. https://datatracker.ietf.org/doc/html/rfc8693#name-request also shows that application/x-www-form-urlencoded is required

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
…d as a separate PR.

Signed-off-by: Sandor Szücs <sandor.szuecs@zalando.de>
@a4180p

a4180p commented Oct 5, 2026

Copy link
Copy Markdown
Member

👍

@zalando-robot

Copy link
Copy Markdown

Docker image "registry-write.opensource.zalan.do/teapot/skipper:d82eb36fd6555854e208e6260c2e81c3b2eb9d58" is not based on an approved base image. Any production deployment relying on this image will be blocked.

To create a compliant Docker image of your application, you must reference an allowed Docker image as its base image in your Dockerfile. This base image must come from the Zalando Container Registry namespace library and use a recommended version as listed in the documentation.

@szuecs
szuecs merged commit 8c1c8f5 into master Oct 5, 2026
23 checks passed
@szuecs
szuecs deleted the feature/token-exchange-rfc-8693 branch October 5, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation enhancement feature definition minor no risk changes, for example new filters

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants