Skip to content

ateapi: fail cleanly on a malformed actor JWT signing pool - #601

Closed
Mesut Oezdil (mesutoezdil) wants to merge 1 commit into
agent-substrate:mainfrom
mesutoezdil:fix/session-jwt-pool-panics
Closed

ateapi: fail cleanly on a malformed actor JWT signing pool#601
Mesut Oezdil (mesutoezdil) wants to merge 1 commit into
agent-substrate:mainfrom
mesutoezdil:fix/session-jwt-pool-panics

Conversation

@mesutoezdil

@mesutoezdil Mesut Oezdil (mesutoezdil) commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

MintJWT indexes Authorities[0] from the actor JWT signing pool file, and actoridjwt.Sign type-asserts the signing key without checking it, so a pool file carrying no authorities (which localjwtauthority.Unmarshal accepts without error) or an algorithm that does not match its key panics instead of returning an error. Nothing in the server installs a panic-recovery interceptor, so that configuration error takes down ate-api-server on the first MintJWT call, and MintCert already guards the same situation for its own pool. This adds the missing checks plus the first tests for both packages, which also pin the behavior of the paths that already worked.

@mesutoezdil Mesut Oezdil (mesutoezdil) changed the title ateapi: fail cleanly on a malformed session JWT signing pool ateapi: fail cleanly on a malformed actor JWT signing pool Jul 30, 2026
@mesutoezdil
Mesut Oezdil (mesutoezdil) force-pushed the fix/session-jwt-pool-panics branch 4 times, most recently from 55cb184 to 8cde094 Compare August 28, 2026 20:01
@ahmedtd

Copy link
Copy Markdown
Collaborator

Apologies, I think this may be superseded by #1313

MintJWT indexes Authorities[0] from the actor JWT signing pool file,
and actoridjwt.Sign type-asserts the signing key without checking it,
so a pool file carrying no authorities (which localjwtauthority.
Unmarshal accepts without error) or an algorithm that does not match
its key panics instead of returning an error. Nothing in the server
installs a panic-recovery interceptor, so that configuration error
takes down ate-api-server on the first MintJWT call, and MintCert
already guards the same situation for its own pool.

Adds the missing checks plus the first tests for both packages,
which also pin the behavior of the paths that already worked.
@mesutoezdil

Copy link
Copy Markdown
Contributor Author

Closing, the file this PR touches will be deleted by #1313 so this diff cannot land as-is. The algorithm/key-type mismatch panic in sign() is still unfixed after #1313 though, I will open a fresh PR against internal/localjwtauthority/localjwtauthority.go once it merges.

@mesutoezdil
Mesut Oezdil (mesutoezdil) deleted the fix/session-jwt-pool-panics branch August 29, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants