G3.2/G3.4: real EPT verification + wire the throttle, reopening agent auth
All checks were successful
check / gate (push) Successful in 21s
All checks were successful
check / gate (push) Successful in 21s
REOPENS the agent path — but only because possession is now actually proven. EPT verification (api/app/ept.py): ES256 against Eternitas's published key set at /.well-known/eternitas-keys. algorithms=['ES256'] makes alg:none and algorithm confusion unrepresentable rather than merely unlikely; issuer and exp are enforced by the library; an unknown kid is refused. Order is deliberate: signature FIRST, trust lookup second. These EPTs live ~365 days and carry rev/tru baked in at issuance, so a year-old 'rev: false' proves nothing — revocation and band still come from a live lookup on every request. Found while building it: real EPTs put the passport in . The old code read /, which no genuine EPT carries — so real agents were never recognised and ONLY forged tokens ever authenticated. The bypass was not just a hole, it was the only thing that worked. Throttle (api/app/throttle.py): BAND_MULTIPLIER and rate_*_per_day were defined and read by nothing. Now enforced on repo.create and grant.create, counted against agent_actions (one source of truth, not a private counter that drifts from the audit log). Fails CLOSED — a limiter that fails open protects you until the moment something is wrong. Untrusted band is 403 read-only, not 429, because 'slow down' would be a lie. Tests: 14 behavioral, signing real ES256 tokens with a locally-generated key so they exercise the crypto path with no network dependency — genuine tokens accepted, and alg:none / foreign key / tampered payload / expired / wrong issuer / unknown kid / missing claims all refused. 74 green. Co-Authored-By: Claude (Fable 5) <noreply@anthropic.com>
This commit is contained in:
@@ -658,23 +658,27 @@ def _fake_request(settings):
|
||||
|
||||
@_pytest.mark.asyncio
|
||||
async def test_security_forged_agent_token_is_refused_in_production():
|
||||
"""A token with alg:none naming a real passport must NOT authenticate.
|
||||
This is the exploit that returned HTTP 200 on 2026-08-13, exercised through
|
||||
the real get_caller decision rather than by grepping for a string."""
|
||||
"""The 2026-08-13 exploit: an alg:none token naming a real passport returned
|
||||
HTTP 200 as that agent. It must now be refused whichever gate catches it —
|
||||
an EPT-shaped forgery by signature verification, a JWT-shaped one by the
|
||||
human gate. What is asserted is REFUSAL, not a particular error code."""
|
||||
from api.app.auth import get_caller
|
||||
from api.app.config import Settings
|
||||
from api.app.errors import RepairPointer
|
||||
|
||||
settings = Settings(environment="production", require_verified_jwt=True,
|
||||
eternitas_platform_api_key="x", eternitas_base_url="https://api.eternitas.ai")
|
||||
eternitas_platform_api_key="x")
|
||||
req = _fake_request(settings)
|
||||
|
||||
with _pytest.raises(RepairPointer) as exc:
|
||||
await get_caller(req, authorization=f"Bearer {_forged_bearer('ET26-1EF9-VJAN')}",
|
||||
x_service_token=None)
|
||||
# Must be refused, and must be refused BEFORE any trust lookup could seat it.
|
||||
assert exc.value.status_code in (401, 503)
|
||||
assert exc.value.code == "agent_signin_not_ready"
|
||||
for typ, expected in (("JWT", "human_signin_not_ready"), ("EPT", "ept_invalid")):
|
||||
def seg(d):
|
||||
return _b64.urlsafe_b64encode(_json.dumps(d).encode()).rstrip(b"=").decode()
|
||||
forged = (f"{seg({'alg':'none','typ':typ})}"
|
||||
f".{seg({'passport':'ET26-1EF9-VJAN','sub':'ET26-1EF9-VJAN'})}.sig")
|
||||
with _pytest.raises(RepairPointer) as exc:
|
||||
await get_caller(req, authorization=f"Bearer {forged}", x_service_token=None)
|
||||
assert exc.value.status_code in (401, 403, 503), f"{typ} was not refused"
|
||||
assert exc.value.code == expected, f"{typ} -> {exc.value.code}"
|
||||
|
||||
|
||||
@_pytest.mark.asyncio
|
||||
|
||||
Reference in New Issue
Block a user