* fixes#3809 support CSR submission during OIDC authentication
- accepts an optional CSR during OIDC login (all auth methods) and
signs it into a session-bound certificate with a SPIFFE ID derived
from the identity and API session
- returns the signed certificate PEM as a top-level "session_cert"
field in the token endpoint JSON response (CodeExchange, RefreshToken,
TokenExchange)
- adds cert-binding verification on RefreshToken and TokenExchange:
if z_cfs is present the peer cert fingerprint must match (strict),
otherwise falls back to SPIFFE ID verification
- supports cert rotation via csr_pem form parameter on refresh and
token exchange; replaces the session cert fingerprint while
preserving the authenticating cert fingerprint
- adds AuthCertFingerprints (z_acfs) claim to track permanent auth
cert fingerprints separately from rotatable session cert fingerprints
- only the leaf certificate fingerprint is added to z_cfs and z_acfs,
intermediates are never included
- invalid CSR returns 400 Bad Request in OIDC error format
- propagates updated CustomClaims (including CertFingerprints) from
access token to renewed refresh token so rotated fingerprints are
enforced on subsequent refreshes
- adds CertGenerated field to ApiSessionEvent
- advertises OIDC_AUTH_WITH_CSR controller capability when OIDC is
enabled
- adds unit tests for verifyCertBinding (fingerprint, SPIFFE ID,
edge cases) and CsrPem field parsing
- adds integration tests for initial CSR auth (updb, cert, ext-jwt),
cert-binding on refresh/exchange, CSR rotation with cert auth,
SPIFFE fallback and z_cfs transition, and CSR property forging
resistance
* address pr concerns
* add z_cfs len tests on junk chain certs
* strip csr subject info, replace w/ santized values
* fix csr rotation rejection/paths during token exchange/refresh
* fixes#3680 add revocation management API, CLI, and enforcement
- adds Management API endpoints for revocations (POST, GET, LIST) with
type-aware validation (JTI/API_SESSION require UUID, IDENTITY requires
existing identity)
- adds CLI commands: ziti edge create revocation identity|api-session|jti
- adds revocation checks to resolveOidcSession in security_ctx.go so the
REST API returns 401 for revoked OIDC tokens. Previously only
ValidateAccessToken (router ctrl channel path) checked revocations,
so revoked tokens still received 200 OK from the management and client
HTTP APIs
- adds api-session revocation check to ValidateAccessToken, which only
checked JTI and identity revocations
- adds Type field to Revocation model, store, and protobuf message
- adds integration tests covering CRUD, input validation, and token
enforcement for all three revocation types
- use release edge-api@v0.28.1
- adds DeleteRevocationsBatchCommand so expired-revocation cleanup goes
through raft as a single log entry per batch
- adds CreateRevocationsBatchCommand for batched revocation creation
through raft
- moves refresh-token revocations from synchronous inline creation to a
background batcher that flushes on a configurable interval, removing
the database and raft as a bottleneck on token refreshes
- skips revocation creation for tokens expiring within a configurable
threshold (revocationMinTokenLifetime), since they become invalid on
their own
- validates that revocationMinTokenLifetime is less than 50% of the
configured refresh token lifetime
- makes the revocation enforcer frequency configurable and restricts it
to run only on the raft leader
- adds tests for multi-batch delete, batched create with router RDM
propagation, and skip-threshold behavior
- adds new configuration tunables under edge.oidc: revocationBucketInterval,
revocationMinTokenLifetime, revocationBucketMaxSize, revocationMaxQueued,
revocationEnforcerFrequency
- fixes RevokeToken double-write: adds return after JWTID-keyed revocation
save, preventing fallthrough write with raw JWT string as unreachable key
- fixes TerminateSession key mismatch: stores revocation by identityId alone,
matching the Subject-based lookup in ValidateAccessToken
- fixes RevocationDelete sync action: passes DataState_Delete instead of
DataState_Create so routers evict the entry from their data model
- adds RevocationManager.DeleteExpired: batch-deletes expired revocations in
batches of 500 until none remain
- adds RevocationEnforcer: periodic policy runner (every 1 minute) that calls
DeleteExpired and records metrics
before test fixes
* fixesopenziti/ziti#3626 omit overlay bind points from /versions apiBaseUrls
- adds BindPointTypeUnderlay and BindPointTypeOverlay constants
- implements Type() on UnderlayBindPoint and OverlayBindPoint
- skips non-underlay bind points when building apiBaseUrls in version_router
- skips non-underlay bind points in GetApiAddresses
- adds unit tests for Type() on both bind point implementations
- updates xweb
* fixes#3597, enable OIDC by default
- adds ability to have different sets of environment configs for tests
- adds ConfigSet struct as a configuration device for integration tests
- allows entire environments to be defined as needed
- original ats config set at "default-ats"
- tests that do not specify a config set, use "default-ats" as before
- standardizes configuration location, naming, etc.
- adds README.md for the above
- updates testContext to now be config set aware
- add config value to disable, update tests, changelog
- add defense against cached version data for tests
* fixesopenziti/ziti#3356 adds www-authenticate headers
- www-authenticate headers are returned on 401s from API requests
- www-authenticate headers are returned during authentication to signal
addtional JWT bearer tokens needed (secondary ext jwt)
- adds support for additional headers on API errors
- adds SecurityTokenCtx for centralized security header processing
(legacy, jwt, etc.)
- adds SecurityCtx for centralized identity, auth policy, MFA handling
- refactors existing JWT authentication methods (oidc, legacy) to use
centralized processing where possible
* add support for and identity-driven bindPoints in controller
* cannot use ListenOptions as it pulls the go sdk into xweb :(
* more generic log message
* add ziti cli login tests in prep for continuing adding identity support in controller
* updates to tests
* updates to tests
* rebase with main
* allow login testing to external overlay
* more changes to allow a zitified ziti cli. add a test for testing login and ensure it works over a zitified connection
* refactor bindPoints to a module
* rebase with main
* no functional changes, just major refactoring based on PR requests. encapsulated all tests state into loginTestState, moved overlay to testutil
* rework a couple of util funcs to be cleaner per PR feedback
* make the new func more useful
* run tests via github action
* update changelog and remove unnecssary serveTls for now
* update from xweb v2 to v3
* change where factory is added and fix compilation issue of a test
* linting changes, move ascode test to cli_tests and activate via cli_tests
* use proper go build
* forgot to set the bin location
* fix timeout on test
* different errors on linux, windows and on gh runners
* cleanup after self-pr review
* use longer name to prevent codespell issues...
* additional changelog and add addressable terminator support
* fix out of control concatenation in cache file. fix ipv6 checking
* updates based on newer sdk and edge api client
* ensure oidc sessions auth for both older and newer commands
* add better error when url is empty and update changelog
* codespell fixes
* remove extraneous file
* update to 1.3.0 to kick off CI
* PR related changes. add interface enforcer and refactor networkIdentity
* go tidied
* fix golangci-lint and ha quickstart test
* keep fixing golanglint-ci... lol
* golanglint i was sure i'd fixed
* fix login test
* should fix ziti ops verify traffic as well
* fix verify traffic when all login information is supplied as well
* make all the timeouts longer? seems to run fine locally but fail in actions
* fixesopenziti/ziti#2324 add token based enrollment
- allows enrollment to certificate auth
- allows enrollment to ext jwt token auth
- alters ext jwt claimsProperty (maps identity id) to support JSON
pointers, defaults to `/sub`
- adds ext jwt enrollToCert, enrollToToken to controller valid
enrollment end-authenticator state
- adds ext jwt enrollAuthPolicyId to map end identity auth policy to,
defaults to `default`
- adds ext jwt enrollAttributeSelector, supports single field name or
JSON pointer to point to a single string or array of string attributes
to give the identity, defaults to no selector
- adds ext jwt enrollNameSelector, supports single field name or JSON
pointer to a string field to use as the name, defaults to `/sub`
- add enrollment errors to determine if enrollment has occurred
- adds CLI support for ext jwt signer enroll flags
* fix#3231 use root controller server certs for OIDC signing
- addresses HA vs non-HA signing
- fixes issue where APIs server w/ difference certs than the root
identity
- adds documentation for env/appenv
- adds a new composite type for TLSCert JWT signers
* address possible nil reference
* remove ineff assignment on jwt signing method
fixes#3084 adds events and improper chain flag
- splits cert resolution into root, legacy root + intermediate,
and third-party pool. Allowing the detection of client authentication
with incomplete chains if root + intermediate succeeds after root only fails
- adds `improperClientCertChain` to API Sessions and Current API Session.
Added for OIDC and legacy auth. Set to true when a client certificate is used
that was issued by the network and did not pass the root-only pool.
* fix#2984 identity/router enrollment do not return full chains
- router extend via REST/ctrl now return full chains
- identity extend via REST now return full chains
- updates tests to allow for chain lengths
- modifies verification to look at the first cert in the chain (leaf)
- modifies edge routers to not start extension if new certs can't be
saved
- adds network-jwt tests
* fixes#2796 generated clients for enrollment do not work
- default behavior complies with OpenAPI spec, but allows for legacy PEM
handling through middleware intervention
- adds test for generic enrollment endpoint and for specific enrollment
endpoints
* fixes#2681 adds targetToken support for ext jwt signers
- adds targetToken of values ACCESS, ID for management API CRUD
- adds targetToken to client API reads
- adds --target-token to external jwt signers CLI
- updates/adds tests
- update client test