coreapi: explain why ENTIRE_TOKEN path has no cluster-trust gate · Entire
coreapi: explain why ENTIRE_TOKEN path has no cluster-trust gate
7491bad→main·
pjbgf·1mo ago·1 file·+17 added/-3 removed
The comment claimed coreapi.New "mirrors" the env-token path in git-remote-entire/main.go, but that path adds a cluster-trust gate (ResolveClusterCores + coreTrusted) that this path lacks — exactly the verification CoreURLFromEnvToken's doc mandates of callers.
Drop the misleading "mirrors" framing and state why the gate is absent: control-plane commands have no user-supplied resource host to anchor the trust check against (coreURL would only ever be the token's own unverified aud), and aud-redirection carries no escalation because the token is sent verbatim as the bearer rather than exchanged as an STS subject_token — the token is its own credential.
Comment-only change; no behavior change.
Assisted-by: Claude Opus 4.7 noreply@anthropic.com Signed-off-by: Paulo Gomes paulo@entire.io
Sessions
1a80c1eb64cfView transcript
Changes
1
internal/coreapi
Mclient.go+17/-3
31 unmodified lines
32
33
34
35
36
37
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
31 unmodified lines
// ENTIRE_TOKEN bypass: CI / workload-identity runners inject a short-
// lived login or sa-session JWT and want control-plane commands to use
// it verbatim, with no contexts.json (the runner never ran `entire
// login`) and no keyring (the runner has none). Mirrors the env-token
// path in cmd/git-remote-entire/main.go:resolveCreds — presence of the
// var (LookupEnv, including blank) commits the CLI to this mode.
// login`) and no keyring (the runner has none). Presence of the var
// (LookupEnv, including blank) commits the CLI to this mode.
//
// Fail-closed: a blank or malformed value is fatal rather than a silent
// fallback to contexts.json, which would mask a misconfigured runner.
// The token's own aud claim becomes the control-plane origin we dial —
// CoreURLFromEnvToken validates aud is a https bare-origin URL, and
// makes that the resource the static bearer is sent to.
//
// NO TRUST GATE — and deliberately so, in contrast to the env-token path
// in cmd/git-remote-entire/main.go:resolveEnvTokenCreds. That path derives
// coreURL from the same unverified aud claim, then gates it through
// clusterdiscovery.ResolveClusterCores + coreTrusted, anchored to the host
// the user typed in the clone URL — exactly the verification
// CoreURLFromEnvToken's doc mandates of callers. We cannot reuse that gate:
// control-plane commands have no user-supplied resource host to anchor
// against, so coreURL would only ever be the token's own (unverified) aud,
// gating it against itself. We skip it because aud-redirection carries no
// escalation here: git-remote uses the env token as an STS subject_token
// (exchanged via repocreds for a repo-scoped credential), whereas coreapi
// sends the token verbatim as the control-plane bearer — the token IS the
// credential, so re-pointing aud at an attacker host requires already
// holding a valid token and yields nothing the holder didn't already have.
if raw, ok := os.LookupEnv(auth.EnvTokenVar); ok {
envToken := strings.TrimSpace(raw)
if envToken == ""
Minternal/coreapi/client.go+17/-3