Skip to content

PAT-2167 Apps Proxy preview links (1/3): config and JWKS key set - #2662

Merged
pepamartinec merged 12 commits into
mainfrom
pepa/PAT-2167_preview-1-keys
Sep 30, 2026
Merged

pepamartinec merged 12 commits into
mainfrom
pepa/PAT-2167_preview-1-keys

Conversation

@pepamartinec

@pepamartinec pepamartinec commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Release Notes

https://linear.app/keboola/issue/PAT-2167

Part 1 of 3 of preview links for dev-mode apps: sandboxes-service mints a 60 s ES256 link, apps-proxy redeems it for a session cookie. This part adds the preview.* config and the JWKS key set. Nothing is wired into request handling yet.

Key entries are parsed by go-jose (jose.JSONWebKey: exact coordinate length, point on the curve). Fetching and caching are ours: go-oidc's RemoteKeySet refetches on every unknown kid (anyone can make us hammer sandboxes-service), never expires old keys and has no body cap; keyfunc/jwkset has refresh and a rate limit, but would still need our own code for failing closed after 1 h without a good fetch, not blocking boot on the first fetch, the 64 KiB cap, no redirects, skipping one bad entry, and fake-clock tests. A failed fetch (including a 200 without a keys field) keeps the last good set, only an explicit {"keys":[]} clears it, and requests that arrive during an unknown-kid refetch wait for it.

Plans for customer communication

None.

Impact analysis

No impact. The new code is not called yet.

Change type

New feature

Justification

Let agents and the kbc-ui iframe open dev-mode apps through a short-lived signed link instead of the kai-preview handshake.

Deployment

Merge & automatic deploy.

Rollback plan

Revert of this PR.

Post release support plan

None.

@linear-code

linear-code Bot commented Sep 29, 2026

Copy link
Copy Markdown

PAT-2167

@pepamartinec
pepamartinec added this pull request to stack #2664 September 29, 2026 14:06
@pepamartinec
pepamartinec marked this pull request as ready for review September 29, 2026 16:16
Copilot AI balanced review requested due to automatic review settings September 29, 2026 16:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@keboola-pr-reviewer-bot keboola-pr-reviewer-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: needs_human (risk 3/5) · profile psgo

New auth/crypto code (JWKS ES256 verification + HMAC session key) in load-bearing apps-proxy needs a human, despite not being wired in yet.

Concerns:

  • internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/jwks.go: New JWKS/ES256 signature-verification crypto in apps-proxy auth path; needs human review of verification rules.
  • internal/pkg/service/appsproxy/config/config.go: Adds HMAC sessionSigningKey (sensitive) and preview auth config; credential handling requires human sign-off.
  • internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/jwks_test.go: Concurrency test uses time.Sleep(100ms); flake risk (coaching, non-blocking).

Suggested reviewers: @keboola/platform-services

Comment thread internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/jwks.go Outdated
Comment thread internal/pkg/service/appsproxy/proxy/apphandler/authproxy/preview/log.go Outdated
@pepamartinec
pepamartinec merged commit 38ca27f into main Sep 30, 2026
38 of 40 checks passed
@pepamartinec
pepamartinec deleted the pepa/PAT-2167_preview-1-keys branch September 30, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants