Goal
- This way users can obtain their own attic tokens configured for their groups/roles.
- Less fragmented authentication and access control in multi-service environments.
Required changes (blue in diagram)
For this to work attic would need to trust the oauth2 provider's public keyset.
0. This should be possible via fetching the key endpoint at startup, thus adding 1 config option (e.g. oauth2_keyset_endpoint).
2. The oauth2 accessToken (JWT format) would contain the current attic-JWT claims inside.
Such that after validating the token, attic can continue as it does today.
I expect the change for incoming requests would be rather simple.
3. A conditional parse step when an oauth2 token is detected.
4. The JWT signature validation would conditionally use the public keyset of the oauth2 provider.
attic_oauth2_jwt_signing.drawio
If such a feature is desired upstream then I can create a PR for this :)
Goal
Required changes (blue in diagram)
For this to work attic would need to trust the oauth2 provider's public keyset.
0. This should be possible via fetching the key endpoint at startup, thus adding 1 config option (e.g.
oauth2_keyset_endpoint).2. The oauth2 accessToken (JWT format) would contain the current attic-JWT claims inside.
Such that after validating the token, attic can continue as it does today.
I expect the change for incoming requests would be rather simple.
3. A conditional parse step when an oauth2 token is detected.
4. The JWT signature validation would conditionally use the public keyset of the oauth2 provider.
attic_oauth2_jwt_signing.drawio
If such a feature is desired upstream then I can create a PR for this :)