Fix JWTIssuedAtFuture for valid iat claim (#1166)
* Add test for ensuring "iat" works with time cache
This commit is contained in:
@@ -20,6 +20,7 @@ This project adheres to [Semantic Versioning](http://semver.org/).
|
|||||||
- #1149, OpenAPI: Change `GET` response type to array - @laughedelic
|
- #1149, OpenAPI: Change `GET` response type to array - @laughedelic
|
||||||
- #1152, Fix RPC failing when having arguments with reserved or uppercase keywords - @mdr1384
|
- #1152, Fix RPC failing when having arguments with reserved or uppercase keywords - @mdr1384
|
||||||
- #905, Fix intermittent empty replies - @steve-chavez
|
- #905, Fix intermittent empty replies - @steve-chavez
|
||||||
|
- #1139, Fix JWTIssuedAtFuture failure for valid iat claim - @steve-chavez
|
||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
|
|||||||
@@ -20,6 +20,7 @@ module PostgREST.Auth (
|
|||||||
) where
|
) where
|
||||||
|
|
||||||
import Control.Lens.Operators
|
import Control.Lens.Operators
|
||||||
|
import Control.Lens (set)
|
||||||
import qualified Data.Aeson as JSON
|
import qualified Data.Aeson as JSON
|
||||||
import qualified Data.HashMap.Strict as M
|
import qualified Data.HashMap.Strict as M
|
||||||
import Data.Time.Clock (UTCTime)
|
import Data.Time.Clock (UTCTime)
|
||||||
@@ -48,7 +49,7 @@ jwtClaims secret audience payload time jspath =
|
|||||||
case secret of
|
case secret of
|
||||||
Nothing -> return JWTMissingSecret
|
Nothing -> return JWTMissingSecret
|
||||||
Just s -> do
|
Just s -> do
|
||||||
let validation = defaultJWTValidationSettings (maybe (const True) (==) audience)
|
let validation = set allowedSkew 1 $ defaultJWTValidationSettings (maybe (const True) (==) audience)
|
||||||
eJwt <- runExceptT $ do
|
eJwt <- runExceptT $ do
|
||||||
jwt <- decodeCompact payload
|
jwt <- decodeCompact payload
|
||||||
verifyClaimsAt validation s time jwt
|
verifyClaimsAt validation s time jwt
|
||||||
|
|||||||
@@ -120,6 +120,29 @@ invalidRoleClaimKey(){
|
|||||||
pgrStop
|
pgrStop
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ensure iat claim is successful in the presence of pgrst time cache, see https://github.com/PostgREST/postgrest/issues/1139
|
||||||
|
ensureIatClaimWorks(){
|
||||||
|
pgrStart "./configs/simple.config"
|
||||||
|
while pgrStarted && test "$( rootStatus )" -ne 200
|
||||||
|
do
|
||||||
|
# wait for the server to start
|
||||||
|
sleep 0.1 \
|
||||||
|
|| sleep 1 # fallback: subsecond sleep is not standard and may fail
|
||||||
|
done
|
||||||
|
for i in {1..10}; do \
|
||||||
|
iatJwt=$(psql -qtAX postgrest_test -c "select jwt.sign(row_to_json(r), 'reallyreallyreallyreallyverysafe') from ( select 'postgrest_test_author' as role, extract(epoch from now()) as iat) r")
|
||||||
|
httpStatus="$( authorsStatus $iatJwt )"
|
||||||
|
if test "$httpStatus" -ne 200
|
||||||
|
then
|
||||||
|
ko "iat claim rejected with $httpStatus"
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
sleep .5;\
|
||||||
|
done
|
||||||
|
ok "accepted iat claim"
|
||||||
|
pgrStop
|
||||||
|
}
|
||||||
|
|
||||||
# PRE: curl must be available
|
# PRE: curl must be available
|
||||||
test -n "$(command -v curl)" || bailOut 'curl is not available'
|
test -n "$(command -v curl)" || bailOut 'curl is not available'
|
||||||
|
|
||||||
@@ -157,6 +180,8 @@ invalidRoleClaimKey '.#$%&$%/'
|
|||||||
invalidRoleClaimKey ''
|
invalidRoleClaimKey ''
|
||||||
invalidRoleClaimKey 1234
|
invalidRoleClaimKey 1234
|
||||||
|
|
||||||
|
ensureIatClaimWorks
|
||||||
|
|
||||||
cleanUp
|
cleanUp
|
||||||
|
|
||||||
exit $failedTests
|
exit $failedTests
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
db-uri = "postgres:///postgrest_test"
|
||||||
|
db-schema = "test"
|
||||||
|
db-anon-role = "postgrest_test_anonymous"
|
||||||
|
db-pool = 1
|
||||||
|
server-host = "127.0.0.1"
|
||||||
|
server-port = 49421
|
||||||
|
jwt-secret = "reallyreallyreallyreallyverysafe"
|
||||||
Reference in New Issue
Block a user