Repository navigation
Conversation
…ibutes (HASI2026203-278) StarletteIASTelemetryMiddleware previously called parse_token() (unverified JWT decode) and promoted sap_gtid/user_uuid to sap.tenancy.tenant_id/user.id span attributes. A remote sender could submit an attacker-signed JWT naming a victim tenant/user to pollute telemetry attribution. Fix: introduce VerifiedIASClaims (frozen dataclass) and TokenVerifier (Callable type alias) as provenance markers in the IAS module. The middleware now requires an explicit token_verifier parameter — if absent it fails closed (no identity attributes stamped, one-time WARNING logged). If the verifier raises for any reason, identity attributes are silently omitted. x-sap-origin (trigger type, not JWT identity) is stamped independently of token verification. parse_token() and AuditClient are unchanged. No new runtime dependencies.
…fication The middleware previously required consumers to implement their own verifier or left identity attributes unverified. IASVerifier auto-configures from VCAP_SERVICES (CF) or IAS_URL (K8s) so agents using the SDK get working signature verification with no extra code. - Add IASVerifier: JWKS-backed verifier, PyJWKClient with key caching, RS256/ES256 algorithm pinning, issuer/audience/exp/nbf enforcement - Add IASVerifier.from_env(): resolves VCAP_SERVICES → identity → xsuaa, then IAS_URL/IAS_CLIENT_ID env vars; raises IASConfigError if nothing found - StarletteIASTelemetryMiddleware auto-calls IASVerifier.from_env() when no token_verifier supplied; logs WARNING + disables identity attrs on failure - Promote cryptography>=44.0.0 to runtime dep (required for RSA/EC key ops) - Add IASConfigError, IASVerifier to sap_cloud_sdk.ias public API - Add 22 unit tests for IASVerifier (from_env variants + __call__ scenarios) - Rewrite middleware tests: add auto-config coverage + retain all regression tests for forged/invalid tokens
Contributor
Author
|
Superseded by #382 (clean branch: fix/ias-telemetry-verified-claims) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
StarletteIASTelemetryMiddlewarewas callingparse_token()— a deliberately unverified JWT decoder — and promoting the decodedsap_gtid/user_uuiddirectly onto OTel span attributes (sap.tenancy.tenant_id,user.id). An attacker could forge a JWT carrying a victim tenant/user ID, submit it to any agent using this SDK, and permanently pollute telemetry attribution.Root cause: no signature verification before stamping security-sensitive span attributes.
Fix (SDK-only — no consumer changes required):
IASVerifierclass — JWKS-backed verifier, auto-configured from the SAP BTP Identity service binding (VCAP_SERVICESon CF,IAS_URLenv var on Kubernetes). Caches signing keys internally and handles key rotation transparently.VerifiedIASClaimsfrozen dataclass — the SDK's provenance marker. Instances can only come from a verifier that ran signature + issuer + algorithm + expiry checks.StarletteIASTelemetryMiddlewarenow auto-configuresIASVerifier.from_env()at construction and uses it to verify every token before stamping identity attributes. No consumer code changes needed.Behaviour change
tenant_id/user.idstampedx-sap-originheaderZero-config usage
Agents that already have an IAS service binding get verified telemetry with zero code changes.
Apps without an IAS service binding
Identity span attributes will not be stamped and a WARNING is logged at startup — the app continues running normally. The previous behaviour (stamping unverified claims) was a security issue, so this is the correct safe default. Bind an SAP Identity service instance to restore them.
For advanced scenarios (e.g. Istio/Kyma already verified the token and double-verification is undesirable), a custom verifier can be passed via
token_verifier=. See IAS user guide for details.Scope
parse_token()is unchanged — still available as an unverified claim extractor (diagnostics, pre-auth inspection).AuditClientis unchanged — already requires explicitcommon.tenant_id; no auto-fill exists.cryptography>=44.0.0promoted from dev-only to runtime dependency (required for RSA/EC key verification).Files changed
src/sap_cloud_sdk/ias/_verifier.pyIASVerifier+IASConfigErrorsrc/sap_cloud_sdk/ias/_token.pyVerifiedIASClaims,TokenVerifiersrc/sap_cloud_sdk/ias/__init__.pyIASVerifier,IASConfigError,VerifiedIASClaims,TokenVerifiersrc/sap_cloud_sdk/core/telemetry/middleware/starlette_a2a.pyIASVerifier; identity attrs only on verified pathpyproject.tomlcryptography>=44.0.0→ runtime deptests/ias/unit/test_verifier.pyIASVerifiertests/ias/unit/test_token.pyVerifiedIASClaims/TokenVerifierteststests/core/unit/telemetry/middleware/test_starlette_a2a.pysrc/sap_cloud_sdk/ias/user-guide.mdIASVerifieras primary approachsrc/sap_cloud_sdk/core/telemetry/user-guide.mdtoken_verifierparameter docs