Problem/Motivation
file_gate_assurance verifies OIDC at redemption (verify_at: redeem) or trusts the mint caller (verify_at: mint / A1). Design note docs/design/piv-cac-webauthn.md deferred A2: File Gate verifies the user OIDC token at mint before issuing the grant.
Deferred because a front-end access token typically has aud = the SPA client, not File Gate. Correct audience pinning rejects it unless the token is exchanged or remapped for File Gate.
GitHub: Wilkes-Liberty/file_gate#36 (implementation work happens there; this issue is the public dual-venue record).
Proposed resolution
- Document and support RFC 8693 token exchange (or IdP audience mapper) so mint receives
aud= File Gate API client. - Reuse
AssuranceVerifierat mint when field is assurance + a mint-time verify setting. - Fail closed on missing/invalid token / wrong
acr/ audience. - Keep A1 as default for callers that cannot do exchange (honest docs).
- Kernel tests; redeem path unchanged (bridge / DPoP still apply at download as configured).
Remaining tasks
- Spec in design note + API.md
- Config surface on assurance field settings
- Verifier wired on mint path with fail-closed behaviour
- Tests for success / wrong aud / low acr / missing token
- Dual-venue status updated on ship
API changes
Optional mint-time user token / exchange requirement when enabled on the field.
Data model changes
None beyond third-party field settings / config schema for the new option.
Comments
Comment #2
jmcerdaFixed in 1.4.0.
Release: https://www.drupal.org/project/file_gate/releases/1.4.0
GitHub: https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.4.0
Comment #4
jmcerdaComment #5
jmcerdaClosed (fixed): mint-time OIDC verification (A2) shipped in 1.4.0 (GH #36).
https://www.drupal.org/project/file_gate/releases/1.4.0
https://github.com/Wilkes-Liberty/file_gate/releases/tag/1.4.0
Comment #6
jmcerdaConfirm Closed (fixed). Work shipped; removing from Open queue.