feat: completed changes for backend to have k8s auth

This commit is contained in:
=
2025-06-06 23:42:56 +05:30
parent 92030884ec
commit 82c2be64a1
4 changed files with 21 additions and 1 deletions
+4
View File
@@ -119,6 +119,10 @@ declare module "@fastify/request-context" {
oidc?: { oidc?: {
claims: Record<string, string>; claims: Record<string, string>;
}; };
kubernetes?: {
namespace: string;
name: string;
};
}; };
identityPermissionMetadata?: Record<string, unknown>; // filled by permission service identityPermissionMetadata?: Record<string, unknown>; // filled by permission service
assumedPrivilegeDetails?: { requesterId: string; actorId: string; actorType: ActorType; projectId: string }; assumedPrivilegeDetails?: { requesterId: string; actorId: string; actorType: ActorType; projectId: string };
@@ -155,6 +155,12 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
oidc: token?.identityAuth?.oidc oidc: token?.identityAuth?.oidc
}); });
} }
if (token?.identityAuth?.kubernetes) {
requestContext.set("identityAuthInfo", {
identityId: identity.identityId,
kubernetes: token?.identityAuth?.kubernetes
});
}
break; break;
} }
case AuthMode.SERVICE_TOKEN: { case AuthMode.SERVICE_TOKEN: {
@@ -11,5 +11,9 @@ export type TIdentityAccessTokenJwtPayload = {
oidc?: { oidc?: {
claims: Record<string, string>; claims: Record<string, string>;
}; };
kubernetes?: {
namespace: string;
name: string;
};
}; };
}; };
@@ -416,7 +416,13 @@ export const identityKubernetesAuthServiceFactory = ({
{ {
identityId: identityKubernetesAuth.identityId, identityId: identityKubernetesAuth.identityId,
identityAccessTokenId: identityAccessToken.id, identityAccessTokenId: identityAccessToken.id,
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN,
identityAuth: {
kubernetes: {
namespace: targetNamespace,
name: targetName
}
}
} as TIdentityAccessTokenJwtPayload, } as TIdentityAccessTokenJwtPayload,
appCfg.AUTH_SECRET, appCfg.AUTH_SECRET,
// akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error // akhilmhdh: for non-expiry tokens you should not even set the value, including undefined. Even for undefined jsonwebtoken throws error