Skip to content

ateapi: fail cleanly on a malformed actor JWT signing pool - #601

Open
Mesut Oezdil (mesutoezdil) wants to merge 1 commit into
agent-substrate:mainfrom
mesutoezdil:fix/session-jwt-pool-panics
Open

ateapi: fail cleanly on a malformed actor JWT signing pool#601
Mesut Oezdil (mesutoezdil) wants to merge 1 commit into
agent-substrate:mainfrom
mesutoezdil:fix/session-jwt-pool-panics

Conversation

@mesutoezdil

@mesutoezdil Mesut Oezdil (mesutoezdil) commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

MintJWT indexes Authorities[0] from the actor JWT signing pool file, and actoridjwt.Sign type-asserts the signing key without checking it, so a pool file carrying no authorities (which localjwtauthority.Unmarshal accepts without error) or an algorithm that does not match its key panics instead of returning an error. Nothing in the server installs a panic-recovery interceptor, so that configuration error takes down ate-api-server on the first MintJWT call, and MintCert already guards the same situation for its own pool. This adds the missing checks plus the first tests for both packages, which also pin the behavior of the paths that already worked.

@mesutoezdil Mesut Oezdil (mesutoezdil) changed the title ateapi: fail cleanly on a malformed session JWT signing pool ateapi: fail cleanly on a malformed actor JWT signing pool Jul 30, 2026
@mesutoezdil
Mesut Oezdil (mesutoezdil) force-pushed the fix/session-jwt-pool-panics branch 2 times, most recently from 8c9c837 to 564de4a Compare August 26, 2026 07:11
MintJWT indexes Authorities[0] from the actor JWT signing pool file,
and actoridjwt.Sign type-asserts the signing key without checking it,
so a pool file carrying no authorities (which localjwtauthority.
Unmarshal accepts without error) or an algorithm that does not match
its key panics instead of returning an error. Nothing in the server
installs a panic-recovery interceptor, so that configuration error
takes down ate-api-server on the first MintJWT call, and MintCert
already guards the same situation for its own pool.

Adds the missing checks plus the first tests for both packages,
which also pin the behavior of the paths that already worked.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant