Skip to content

feat: signer_address claim on developer JWTs - #332

Open
zer0stars wants to merge 2 commits into
masterfrom
feat/signer-address-claim
Open

zer0stars wants to merge 2 commits into
masterfrom
feat/signer-address-claim

Conversation

@zer0stars

Copy link
Copy Markdown
Member

Why

Developer JWTs name the license (ethereum_address = client ID) but not the API key (license signer) that minted them. Disabling a signer stops new tokens, but existing ones keep working for their full 336 hours. token-exchange-api, vehicle-triggers-api, tesla-oracle and credit-tracker will check isSigner(signer_address) on each request; this is the first half.

What

  • web3 connector: after a successful ERC-1271 verification with a plain 65-byte ECDSA signature, it recovers the signing EOA (the same recovery the license account does before isSigner). It stores the address in Identity.ConnectorData as {"signer_address": "0x…"}.
    • ZeroDev Kernel v3.1 logins (the console's) have longer signatures and get nothing.
    • EOA logins are unchanged.
    • The claim is emitted whatever the client ID. Other 65-byte ERC-1271 wallets get a claim that means nothing; consumers only check it when ethereum_address is a developer license.
  • exchangeAuthCode: reads that connector data, and newIDToken emits signer_address (checksummed) on both the access token and the ID token.
    • Connector data already lives in the existing auth_request and auth_code columns, so there is no storage migration.
    • Only the authorization-code flow sets it. Implicit and hybrid responses don't, and production enables only code.

Release

Don't merge until all four dex deployments are pinned to v2.30.100 (dev, prod, roles-rights dev, roles-rights prod; a cluster-helm-charts PR, not opened yet). Today they all run dimozone/dex:latest with pullPolicy: Always, and a merge here republishes latest, so any pod restart would pick this up unreleased.

  • v2.30.100 is already tagged at the current master (c13c657), and its image is on Docker Hub.
  • After merge, tag v2.30.101 and pin dev only. Production follows after the console-teams live pass in dev.

Successor services

dauth isn't live. If it replaces dex, it must emit the same claim.

Tests

  • TestRecoverSigner.
  • Updated ERC-1271 cases in TestEOALogin and TestBlockchainBackend.
  • TestExchangeAuthCodeSignerAddressClaim: present, absent, another connector's data, malformed, non-JSON.
  • TestSubmitChallengeSignerAddressClaim: end to end through generate_challenge → finalizeLogin → code → token, with a stub Web3 connector, with and without a signer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant