This repository has been archived by the owner on Apr 26, 2024. It is now read-only.
-
-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add an admin endpoint to allow authorizing server to signal token rev…
…ocations (#16125)
- Loading branch information
Showing
10 changed files
with
223 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
Add an admin endpoint to allow authorizing server to signal token revocations. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
# Copyright 2023 The Matrix.org Foundation C.I.C | ||
# | ||
# Licensed under the Apache License, Version 2.0 (the "License"); | ||
# you may not use this file except in compliance with the License. | ||
# You may obtain a copy of the License at | ||
# | ||
# http://www.apache.org/licenses/LICENSE-2.0 | ||
# | ||
# Unless required by applicable law or agreed to in writing, software | ||
# distributed under the License is distributed on an "AS IS" BASIS, | ||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
# See the License for the specific language governing permissions and | ||
# limitations under the License. | ||
from http import HTTPStatus | ||
from typing import TYPE_CHECKING, Dict, Tuple | ||
|
||
from synapse.http.servlet import RestServlet | ||
from synapse.http.site import SynapseRequest | ||
from synapse.rest.admin._base import admin_patterns, assert_requester_is_admin | ||
|
||
if TYPE_CHECKING: | ||
from synapse.server import HomeServer | ||
|
||
|
||
class OIDCTokenRevocationRestServlet(RestServlet): | ||
""" | ||
Delete a given token introspection response - identified by the `jti` field - from the | ||
introspection token cache when a token is revoked at the authorizing server | ||
""" | ||
|
||
PATTERNS = admin_patterns("/OIDC_token_revocation/(?P<token_id>[^/]*)") | ||
|
||
def __init__(self, hs: "HomeServer"): | ||
super().__init__() | ||
auth = hs.get_auth() | ||
|
||
# If this endpoint is loaded then we must have enabled delegated auth. | ||
from synapse.api.auth.msc3861_delegated import MSC3861DelegatedAuth | ||
|
||
assert isinstance(auth, MSC3861DelegatedAuth) | ||
|
||
self.auth = auth | ||
self.store = hs.get_datastores().main | ||
|
||
async def on_DELETE( | ||
self, request: SynapseRequest, token_id: str | ||
) -> Tuple[HTTPStatus, Dict]: | ||
await assert_requester_is_admin(self.auth, request) | ||
|
||
self.auth._token_cache.invalidate(token_id) | ||
|
||
# make sure we invalidate the cache on any workers | ||
await self.store.stream_introspection_token_invalidation((token_id,)) | ||
|
||
return HTTPStatus.OK, {} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,62 @@ | ||
# Copyright 2023 The Matrix.org Foundation C.I.C. | ||
# | ||
# Licensed under the Apache License, Version 2.0 (the "License"); | ||
# you may not use this file except in compliance with the License. | ||
# You may obtain a copy of the License at | ||
# | ||
# http://www.apache.org/licenses/LICENSE-2.0 | ||
# | ||
# Unless required by applicable law or agreed to in writing, software | ||
# distributed under the License is distributed on an "AS IS" BASIS, | ||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
# See the License for the specific language governing permissions and | ||
# limitations under the License. | ||
|
||
from typing import Any, Dict | ||
|
||
import synapse.rest.admin._base | ||
|
||
from tests.replication._base import BaseMultiWorkerStreamTestCase | ||
|
||
|
||
class IntrospectionTokenCacheInvalidationTestCase(BaseMultiWorkerStreamTestCase): | ||
servlets = [synapse.rest.admin.register_servlets] | ||
|
||
def default_config(self) -> Dict[str, Any]: | ||
config = super().default_config() | ||
config["disable_registration"] = True | ||
config["experimental_features"] = { | ||
"msc3861": { | ||
"enabled": True, | ||
"issuer": "some_dude", | ||
"client_id": "ID", | ||
"client_auth_method": "client_secret_post", | ||
"client_secret": "secret", | ||
} | ||
} | ||
return config | ||
|
||
def test_stream_introspection_token_invalidation(self) -> None: | ||
worker_hs = self.make_worker_hs("synapse.app.generic_worker") | ||
auth = worker_hs.get_auth() | ||
store = self.hs.get_datastores().main | ||
|
||
# add a token to the cache on the worker | ||
auth._token_cache["open_sesame"] = "intro_token" # type: ignore[attr-defined] | ||
|
||
# stream the invalidation from the master | ||
self.get_success( | ||
store.stream_introspection_token_invalidation(("open_sesame",)) | ||
) | ||
|
||
# check that the cache on the worker was invalidated | ||
self.assertEqual(auth._token_cache.get("open_sesame"), None) # type: ignore[attr-defined] | ||
|
||
# test invalidating whole cache | ||
for i in range(0, 5): | ||
auth._token_cache[f"open_sesame_{i}"] = f"intro_token_{i}" # type: ignore[attr-defined] | ||
self.assertEqual(len(auth._token_cache), 5) # type: ignore[attr-defined] | ||
|
||
self.get_success(store.stream_introspection_token_invalidation((None,))) | ||
|
||
self.assertEqual(len(auth._token_cache), 0) # type: ignore[attr-defined] |