G3.2/G3.4: real EPT verification + wire the throttle, reopening agent auth
All checks were successful
check / gate (push) Successful in 21s

REOPENS the agent path — but only because possession is now actually proven.

EPT verification (api/app/ept.py): ES256 against Eternitas's published key set
at /.well-known/eternitas-keys. algorithms=['ES256'] makes alg:none and
algorithm confusion unrepresentable rather than merely unlikely; issuer and exp
are enforced by the library; an unknown kid is refused.

Order is deliberate: signature FIRST, trust lookup second. These EPTs live ~365
days and carry rev/tru baked in at issuance, so a year-old 'rev: false' proves
nothing — revocation and band still come from a live lookup on every request.

Found while building it: real EPTs put the passport in . The old code read
/, which no genuine EPT carries — so real agents were
never recognised and ONLY forged tokens ever authenticated. The bypass was not
just a hole, it was the only thing that worked.

Throttle (api/app/throttle.py): BAND_MULTIPLIER and rate_*_per_day were defined
and read by nothing. Now enforced on repo.create and grant.create, counted
against agent_actions (one source of truth, not a private counter that drifts
from the audit log). Fails CLOSED — a limiter that fails open protects you until
the moment something is wrong. Untrusted band is 403 read-only, not 429, because
'slow down' would be a lie.

Tests: 14 behavioral, signing real ES256 tokens with a locally-generated key so
they exercise the crypto path with no network dependency — genuine tokens
accepted, and alg:none / foreign key / tampered payload / expired / wrong issuer
/ unknown kid / missing claims all refused. 74 green.

Co-Authored-By: Claude (Fable 5) <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-13 23:08:40 -04:00
parent c257cc55c6
commit a598c931ef
7 changed files with 528 additions and 42 deletions

View File

@@ -658,23 +658,27 @@ def _fake_request(settings):
@_pytest.mark.asyncio
async def test_security_forged_agent_token_is_refused_in_production():
"""A token with alg:none naming a real passport must NOT authenticate.
This is the exploit that returned HTTP 200 on 2026-08-13, exercised through
the real get_caller decision rather than by grepping for a string."""
"""The 2026-08-13 exploit: an alg:none token naming a real passport returned
HTTP 200 as that agent. It must now be refused whichever gate catches it —
an EPT-shaped forgery by signature verification, a JWT-shaped one by the
human gate. What is asserted is REFUSAL, not a particular error code."""
from api.app.auth import get_caller
from api.app.config import Settings
from api.app.errors import RepairPointer
settings = Settings(environment="production", require_verified_jwt=True,
eternitas_platform_api_key="x", eternitas_base_url="https://api.eternitas.ai")
eternitas_platform_api_key="x")
req = _fake_request(settings)
with _pytest.raises(RepairPointer) as exc:
await get_caller(req, authorization=f"Bearer {_forged_bearer('ET26-1EF9-VJAN')}",
x_service_token=None)
# Must be refused, and must be refused BEFORE any trust lookup could seat it.
assert exc.value.status_code in (401, 503)
assert exc.value.code == "agent_signin_not_ready"
for typ, expected in (("JWT", "human_signin_not_ready"), ("EPT", "ept_invalid")):
def seg(d):
return _b64.urlsafe_b64encode(_json.dumps(d).encode()).rstrip(b"=").decode()
forged = (f"{seg({'alg':'none','typ':typ})}"
f".{seg({'passport':'ET26-1EF9-VJAN','sub':'ET26-1EF9-VJAN'})}.sig")
with _pytest.raises(RepairPointer) as exc:
await get_caller(req, authorization=f"Bearer {forged}", x_service_token=None)
assert exc.value.status_code in (401, 403, 503), f"{typ} was not refused"
assert exc.value.code == expected, f"{typ} -> {exc.value.code}"
@_pytest.mark.asyncio