auth: token contract v1 (aud windy_git, both issuers); CI for eternitas
Some checks failed
check / gate (push) Successful in 37s
canary / probe (push) Has been cancelled

- hub_jwt: aud list is ["windy_git"] (contract v1 array). Dropped
  "windy-git": that is Gitea's OIDC client_id, so a forge id_token would
  have passed the aud check. `type: human` is now REQUIRED (id_tokens have
  none), which makes accepting the discovery-URL issuer safe.
- runner job ceiling 30m -> 90m: eternitas's serial pytest is ~50 min and
  would have been killed mid-suite.
- eternitas (private) added to the GitHub status bridge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 02:58:56 -04:00
parent 18ea9a4686
commit 5b16114b98
6 changed files with 43 additions and 22 deletions

View File

@@ -314,7 +314,7 @@ def test_g36_unverified_human_jwt_is_refused_in_production():
from api.app.config import Settings
assert Settings().require_verified_jwt is True
assert Settings().hub_issuers == ["windy-identity"]
assert "windy-git" not in Settings().hub_audiences # Gitea's client_id: id_token confusion
def test_no_auth_bypass_env_var_anywhere():