PelicanPlatform / pelican

The Pelican Platform for creating data federations
https://pelicanplatform.org/
Apache License 2.0
8 stars 18 forks source link

Token recipients should enforce expected profiles #741

Open jhiemstrawisc opened 5 months ago

jhiemstrawisc commented 5 months ago

With the addition of #719, Pelican generates a lot more WLCG-conformant tokens. We use these tokens for everything from advertising namespaces to directors, to managing access to metrics scraping. Right now we aren't 100% on top of verifying that the received tokens are also conformant. We should go through token transactions and make sure both sides are checking everything they need to be.

jhiemstrawisc commented 2 months ago

Bumping to 7.9 and marking as critical to guarantee this doesn't get bumped again

jhiemstrawisc commented 1 month ago

As this is mostly a "cleanup" item, I'm unfortunately bumping to 7.10 so I can take care of this in our burndown.