feat(server): wire OpenID Federation self-issuance into server.Config - #258
Merged
Conversation
Mirrors client's own federation.SelfIssuer glue (previous PR): adds server.Config.Federation (optional, "zero disables the feature" like every other opt-in capability here) and server.Server.EntityConfiguration, resolving this server's own federation signing key from Dependencies.Keys under the keys.FederationEntitySigning purpose added in that PR, building its JWKS, and signing whatever metadata the caller supplies (typically a federation_entity object plus an openid_provider object mirroring this server's own Metadata). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017N2kkxv9BR4Qmj8De3Ucs6
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
federation.SelfIssuerglue (feat(client): wire OpenID Federation self-issuance into client.Config #257): addsserver.Config.Federation(optional — zero value disables it entirely, matching this package's existing "zero disables the feature" precedent) andserver.Server.EntityConfiguration.Dependencies.Keysunder thekeys.FederationEntitySigningpurpose added in feat(client): wire OpenID Federation self-issuance into client.Config #257, builds its JWKS viakeys.PublicJWKS, and signs whatever metadata the caller supplies — typically afederation_entityobject plus anopenid_providerobject mirroring this server's ownMetadata. It does not derive that metadata fromConfigitself.Test plan
go build ./...go test -race ./...golangci-lint run ./...— 0 issuesConfig.Federationvalidation (invalid entity ID, zero lifetime, zero algorithm; zero-valueFederationleavesEntityConfigurationfailing), a full round trip (sign → parse → verify against the statement's own claimed jwks → checkauthority_hints/metadata pass through), and two dependency-failure paths (key manager failure, key manager returning an empty kid).serverpackage coverage: 87.2%🤖 Generated with Claude Code
https://claude.ai/code/session_017N2kkxv9BR4Qmj8De3Ucs6