Conversation
…entity StarletteIASTelemetryMiddleware was calling parse_token() (unverified JWT decoder) and promoting sap_gtid/user_uuid onto OTel span attributes and the IAS auth context. An attacker could forge a JWT carrying a victim tenant/user ID and permanently pollute telemetry and AuditClient attribution. - Add IASVerifier: JWKS-backed verifier with PyJWKClient, RS256/ES256 alg pinning, issuer/audience/exp/nbf enforcement, key caching and rotation - Add IASVerifier.from_env(): auto-configures from VCAP_SERVICES (CF) or IAS_URL/IAS_CLIENT_ID env vars (K8s); raises IASConfigError if not found - Add VerifiedIASClaims frozen dataclass as provenance marker; add TokenVerifier type alias to sap_cloud_sdk.ias public API - StarletteIASTelemetryMiddleware auto-calls IASVerifier.from_env() at init; logs WARNING and disables identity attrs if no binding found (fail-closed) - _verify_and_extract calls verifier once per request; verified IASClaims flow to both set_auth_context (AuditClient) and OTel span attrs — forged tokens result in None auth context and empty identity attrs - parse_token() unchanged — available as unverified diagnostic decoder - 488 tests pass (22 new for IASVerifier, rewritten middleware tests with auto-config and auth-context coverage)
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
StarletteIASTelemetryMiddlewarewas callingparse_token()— a deliberately unverified JWT decoder — and promoting the decodedsap_gtid/user_uuiddirectly onto OTel span attributes (sap.tenancy.tenant_id,user.id) and the IAS auth context (used by AuditClient auto-fill). An attacker could forge a JWT carrying a victim tenant/user ID and permanently pollute telemetry and audit attribution.Root cause: no signature verification before stamping security-sensitive span attributes or setting the auth context.
Fix (SDK-only — no consumer changes required):
IASVerifierclass — JWKS-backed verifier, auto-configured from the SAP BTP Identity service binding (VCAP_SERVICESon CF,IAS_URLenv var on Kubernetes). Caches signing keys internally and handles key rotation transparently.VerifiedIASClaimsfrozen dataclass — the SDK's provenance marker. Instances can only come from a verifier that ran signature + issuer + algorithm + expiry checks.StarletteIASTelemetryMiddlewarenow auto-configuresIASVerifier.from_env()at construction. Verified claims flow to bothset_auth_contextand OTel span attrs — forged tokens result inNoneauth context and empty identity attrs. No consumer code changes needed.Behaviour change
tenant_id/user.idstamped and in auth contextNonex-sap-originheaderZero-config usage
Agents that already have an IAS service binding get verified telemetry and auth context with zero code changes.
Apps without an IAS service binding
Identity span attributes will not be stamped and a WARNING is logged at startup — the app continues running normally. Bind an SAP Identity service instance to restore them.
For advanced scenarios (e.g. Istio/Kyma already verified the token), a custom verifier can be passed via
token_verifier=. See IAS user guide for details.Scope
parse_token()is unchanged — still available as an unverified claim extractor (diagnostics, pre-auth inspection).AuditClientis unchanged —set_auth_contextnow only receives verified claims, so any auto-fill downstream is also protected.Files changed
src/sap_cloud_sdk/ias/_verifier.pyIASVerifier+IASConfigErrorsrc/sap_cloud_sdk/ias/_token.pyVerifiedIASClaims,TokenVerifiersrc/sap_cloud_sdk/ias/__init__.pyget_auth_context,set_auth_contextsrc/sap_cloud_sdk/core/telemetry/middleware/starlette_a2a.pyIASVerifier; verified claims to both auth context and OTel attrstests/ias/unit/test_verifier.pyIASVerifiertests/core/unit/telemetry/middleware/test_starlette_a2a.py