Skip to content

Keystone Connector: Project scoped token and multi domain login support - #84

Merged
srm6867 merged 6 commits into
masterfrom
private/sm/new-kaap-2399
Sep 30, 2026
Merged

srm6867 merged 6 commits into
masterfrom
private/sm/new-kaap-2399

Conversation

@srm6867

@srm6867 srm6867 commented Sep 23, 2026 •

Copy link
Copy Markdown

Overview

  • Adds two independent, optional params to Keystone-based login — domain_id (which Keystone domain a user logs into) and project_id (which project's permissions get loaded into the token).

What this PR does

  • Lets a user log in against any Keystone domain, not just one fixed default — the caller specifies domain ID at login time.
  • Lets a login be scoped to one project, so the resulting token only carries that project's permissions instead of every project the user has access to
  • Both of the above are optional — a caller that doesn't use them sees no change in behavior.
  • Domain- and system-level permissions are unaffected either way — they still show up in full regardless of project scoping.
  • Works for both the product UI (passes this fields as request param) and kubeconfig oidc-logins (OIDC scope field).
  • existing tokens and token request keep working.

Why we need it

  • JWT bloat: today's login token lists every project-role a user has in one token — this grows unbounded and causes failure for size limits in API reqs. So scoping to specific project fixes this.
  • Multi-domain login support: Users other than default domain couldn't login today. so added domain_id param which can be used for login to other domain than default.

Manual testing

  1. Verified token gets only project scoped role groups-
/dex/token with 
--data-urlencode 'project_id=321c21df221a46d5b726871a72943b8a' \
--data-urlencode 'domain_id=89b2c0236c1a449a939c182b221ff52d'

gives token groups -

  "groups": [
    "test-du-ciprsmoke-5037757-sales-service-admin",
    "test-du-ciprsmoke-5037757-platform_admin"
  ],
  1. Verified token gets roles for all projects when no projectid provided.
  "groups": [
    "test-du-ciprsmoke-5037757-sales-service-admin",
    "test-du-ciprsmoke-5037757-sales-with-capital-admin",
    "test-du-ciprsmoke-5037757-sales-pune-tenant_admin",
    "test-du-ciprsmoke-5037757-platform_admin"
  ]
  1. Verified domain_id can be used to login to different domains
  2. Verified kubeconfig oidc-login can pass projectid and domainid via scope field
--oidc-extra-scope=groups,email,profile,offline_access,project:321c21df221a46d5b726871a72943b8a,domain:89b2c0236c1a449a939c182b221ff52d

@srm6867
srm6867 requested a review from a team September 23, 2026 06:03
Comment thread connector/keystone/keystone.go
Comment thread connector/keystone/keystone.go Outdated
Comment thread server/oauth2.go
@srm6867
srm6867 merged commit 5270395 into master Sep 30, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants