-
Notifications
You must be signed in to change notification settings - Fork 116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
refactor(router): redesign JWK authentication logic #1498
refactor(router): redesign JWK authentication logic #1498
Conversation
Router image scan passed✅ No security vulnerabilities found in image:
|
cc46adb
to
eadd615
Compare
b924099
to
d9d341b
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Overall great work. Just a few nuts.
Please document how the migration will look like and mention that it is breaking. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
I will prepare the documentation changes before merging this PR |
* feat: expose type data and record subgraphs for enums (wundergraph#1495) * chore(release): Publish [skip ci] - [email protected] - [email protected] - @wundergraph/[email protected] - [email protected] - @wundergraph/[email protected] - [email protected] * feat: improve rate limit responses (add code, hide stats) (wundergraph#1497) * chore(release): Publish [skip ci] - [email protected] * fix: provider should be specified in the config.yaml (wundergraph#1397) * fix: update the timeouts for clickhouse and platform service (wundergraph#1500) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] * fix: add edfs to the demo environment (wundergraph#1505) * docs(CONTRIBUTING): fixup minor mistake in CONTRIBUTING.md under Go workspace (wundergraph#1502) Co-authored-by: Dustin Deus <[email protected]> * fix: full demo broken in main branch (wundergraph#1508) * feat(router): optionally add jitter to config polling interval (wundergraph#1506) Co-authored-by: Dustin Deus <[email protected]> * chore(release): Publish [skip ci] - [email protected] * fix(router): remove wildcard from router graphql path (wundergraph#1509) * fix: use gauge for server.uptime metric (wundergraph#1510) Co-authored-by: Ludwig <[email protected]> * feat: cache warmer (wundergraph#1501) Co-authored-by: Ludwig <[email protected]> Co-authored-by: starptech <[email protected]> * chore(release): Publish [skip ci] - [email protected] - @wundergraph/[email protected] - [email protected] - @wundergraph/[email protected] - [email protected] - [email protected] - [email protected] - @wundergraph/[email protected] - [email protected] * fix(cache warmup): consider only po of the last 7 days (wundergraph#1513) * chore(release): Publish [skip ci] - [email protected] * fix(cache operation): swallow cache errors and other improvements (wundergraph#1515) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] - [email protected] * feat: add variables remapping support (wundergraph#1516) Co-authored-by: starptech <[email protected]> * chore(release): Publish [skip ci] - [email protected] * fix(router): write proper line endings and header for multipart (wundergraph#1517) * chore(release): Publish [skip ci] - [email protected] * feat(router): optimize playground delivery, add concurrency_limit to config (wundergraph#1519) * fix(router): enable health checks during startup (wundergraph#1529) * feat: improve cache warmer (wundergraph#1530) Co-authored-by: Ludwig <[email protected]> * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] * fix: remove semaphore from ResolveGraphQLSubscription (wundergraph#1532) * chore(release): Publish [skip ci] - [email protected] * feat: add compatibility handshake between router and execution config (wundergraph#1534) * chore(release): Publish [skip ci] - [email protected] - @wundergraph/[email protected] - @wundergraph/[email protected] - [email protected] - [email protected] - @wundergraph/[email protected] - [email protected] * feat: also add handshake for static execution configs (wundergraph#1535) * chore(router): bump demo library to pickup subscription fix (wundergraph#1518) * feat(router): add interface for trace propagation (wundergraph#1526) * chore(release): Publish [skip ci] - [email protected] * fix: adding/removing directive is not picked up by wgc subgraph check (wundergraph#1494) * chore(deps): upgrade ristretto to v2 (wundergraph#1538) * feat: add normalizedQuery to query plan and request info to trace (wundergraph#1536) Co-authored-by: df-wg <[email protected]> * fix: add copy button to subgraph routing url (wundergraph#1543) Co-authored-by: Dustin Deus <[email protected]> * fix: webhooks shot when schema is unchanged (wundergraph#1542) * fix: trim the inputs of group mappers (wundergraph#1541) * fix: subgraphs search functionality (wundergraph#1540) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] - [email protected] * fix: increase max concurrent resolvers (wundergraph#1544) * refactor(router): redesign JWK authentication logic (wundergraph#1498) * chore(release): Publish [skip ci] - [email protected] * fix: increase the test timeout value to prevent failures on slower machines (wundergraph#1547) * fix: reduce the breaking change retention duration (wundergraph#1550) * fix: change the defaults of breaking-change-retention (wundergraph#1551) * feat(router): enable starting the router without subgraphs (wundergraph#1533) * fix(router): parse accept header per rfc 9110 (wundergraph#1549) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] * feat(router): enable using redis clusters for rate limiting and apq (wundergraph#1499) * fix: json schema for traffic shaping subgraphs (wundergraph#1552) * chore: Update aws-lambda-router customisation after upstream sync --------- Co-authored-by: Nithin Kumar B <[email protected]> Co-authored-by: hardworker-bot <[email protected]> Co-authored-by: Jens Neuse <[email protected]> Co-authored-by: Alessandro Pagnin <[email protected]> Co-authored-by: Suvij Surya <[email protected]> Co-authored-by: endigma <[email protected]> Co-authored-by: Dustin Deus <[email protected]> Co-authored-by: Ludwig <[email protected]> Co-authored-by: Sergiy 🇺🇦 <[email protected]> Co-authored-by: df-wg <[email protected]> Co-authored-by: Aenimus <[email protected]>
* feat: expose type data and record subgraphs for enums (wundergraph#1495) * chore(release): Publish [skip ci] - [email protected] - [email protected] - @wundergraph/[email protected] - [email protected] - @wundergraph/[email protected] - [email protected] * feat: improve rate limit responses (add code, hide stats) (wundergraph#1497) * chore(release): Publish [skip ci] - [email protected] * fix: provider should be specified in the config.yaml (wundergraph#1397) * fix: update the timeouts for clickhouse and platform service (wundergraph#1500) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] * fix: add edfs to the demo environment (wundergraph#1505) * docs(CONTRIBUTING): fixup minor mistake in CONTRIBUTING.md under Go workspace (wundergraph#1502) Co-authored-by: Dustin Deus <[email protected]> * fix: full demo broken in main branch (wundergraph#1508) * feat(router): optionally add jitter to config polling interval (wundergraph#1506) Co-authored-by: Dustin Deus <[email protected]> * chore(release): Publish [skip ci] - [email protected] * fix(router): remove wildcard from router graphql path (wundergraph#1509) * fix: use gauge for server.uptime metric (wundergraph#1510) Co-authored-by: Ludwig <[email protected]> * feat: cache warmer (wundergraph#1501) Co-authored-by: Ludwig <[email protected]> Co-authored-by: starptech <[email protected]> * chore(release): Publish [skip ci] - [email protected] - @wundergraph/[email protected] - [email protected] - @wundergraph/[email protected] - [email protected] - [email protected] - [email protected] - @wundergraph/[email protected] - [email protected] * fix(cache warmup): consider only po of the last 7 days (wundergraph#1513) * chore(release): Publish [skip ci] - [email protected] * fix(cache operation): swallow cache errors and other improvements (wundergraph#1515) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] - [email protected] * feat: add variables remapping support (wundergraph#1516) Co-authored-by: starptech <[email protected]> * chore(release): Publish [skip ci] - [email protected] * fix(router): write proper line endings and header for multipart (wundergraph#1517) * chore(release): Publish [skip ci] - [email protected] * feat(router): optimize playground delivery, add concurrency_limit to config (wundergraph#1519) * fix(router): enable health checks during startup (wundergraph#1529) * feat: improve cache warmer (wundergraph#1530) Co-authored-by: Ludwig <[email protected]> * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] * fix: remove semaphore from ResolveGraphQLSubscription (wundergraph#1532) * chore(release): Publish [skip ci] - [email protected] * feat: add compatibility handshake between router and execution config (wundergraph#1534) * chore(release): Publish [skip ci] - [email protected] - @wundergraph/[email protected] - @wundergraph/[email protected] - [email protected] - [email protected] - @wundergraph/[email protected] - [email protected] * feat: also add handshake for static execution configs (wundergraph#1535) * chore(router): bump demo library to pickup subscription fix (wundergraph#1518) * feat(router): add interface for trace propagation (wundergraph#1526) * chore(release): Publish [skip ci] - [email protected] * fix: adding/removing directive is not picked up by wgc subgraph check (wundergraph#1494) * chore(deps): upgrade ristretto to v2 (wundergraph#1538) * feat: add normalizedQuery to query plan and request info to trace (wundergraph#1536) Co-authored-by: df-wg <[email protected]> * fix: add copy button to subgraph routing url (wundergraph#1543) Co-authored-by: Dustin Deus <[email protected]> * fix: webhooks shot when schema is unchanged (wundergraph#1542) * fix: trim the inputs of group mappers (wundergraph#1541) * fix: subgraphs search functionality (wundergraph#1540) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] - [email protected] * fix: increase max concurrent resolvers (wundergraph#1544) * refactor(router): redesign JWK authentication logic (wundergraph#1498) * chore(release): Publish [skip ci] - [email protected] * fix: increase the test timeout value to prevent failures on slower machines (wundergraph#1547) * fix: reduce the breaking change retention duration (wundergraph#1550) * fix: change the defaults of breaking-change-retention (wundergraph#1551) * feat(router): enable starting the router without subgraphs (wundergraph#1533) * fix(router): parse accept header per rfc 9110 (wundergraph#1549) * chore(release): Publish [skip ci] - [email protected] - [email protected] - [email protected] * feat(router): enable using redis clusters for rate limiting and apq (wundergraph#1499) * fix: json schema for traffic shaping subgraphs (wundergraph#1552) * fix: subgraph timeout can't be bigger than global timeout (wundergraph#1548) * fix: error when graph token is not set when cache warmup is enabled (wundergraph#1554) * chore(release): Publish [skip ci] - [email protected] * fix: incorrect graphql endpoint in playground (wundergraph#1562) * chore(release): Publish [skip ci] - @wundergraph/[email protected] - [email protected] * fix: update vulnerable packages (wundergraph#1560) * fix: synchronize go mod versions (wundergraph#1564) * chore: reduce verbose logging for failed tests (wundergraph#1565) * fix: Add missing config mapping, bump aws-lambda-router version * fix: Repair PNPM lockfile after merge --------- Co-authored-by: Nithin Kumar B <[email protected]> Co-authored-by: hardworker-bot <[email protected]> Co-authored-by: Jens Neuse <[email protected]> Co-authored-by: Alessandro Pagnin <[email protected]> Co-authored-by: Suvij Surya <[email protected]> Co-authored-by: endigma <[email protected]> Co-authored-by: Dustin Deus <[email protected]> Co-authored-by: Ludwig <[email protected]> Co-authored-by: Sergiy 🇺🇦 <[email protected]> Co-authored-by: df-wg <[email protected]> Co-authored-by: Aenimus <[email protected]>
Motivation and Context
The current implementation for the authentication logic is not optimal. We are creating a token decoder per JWKs while the intention for the library is to have multiple sources where a keyset can be loaded and refreshed from.
This PR introduces a redesign of the current implementation. The configuration changes from a per JWKS basis to a global config with some options per JWKs (e.g. whitelisting algorithms when loading keys)
The token logic has been simplified to use a single token decoder, that can handle all keys and header/valueprefix combinations.
Warning
As part of the preparations for Cosmo V1, targeted for release in Q1 2025, this pull request introduces essential changes to enhance long-term stability and maintainability. While we strive to minimize breaking changes, they are sometimes necessary to lay the foundation for a more robust and scalable system.
Config change example:
Checklist