Securing identity token forwarding
Methods, systems, and computer-readable storage media for receiving, from a first component and by a second component in a cloud platform, a call, a token, and a first client certificate, determining, by the second component, a first client identifier associated with the first component, and determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response: executing functionality responsive to the call.
1. A computer-implemented method for secure access token forwarding between components in cloud platforms, the method being executed by one or more processors and comprising:
receiving, from a first component and by a second component in a cloud platform, a first call, a token, and a first client certificate; wherein the token provided to the first component in response to a request from the first component to a central identity and authentication service (IAS) of the cloud platform, and the first client certificate is provided during execution of a process to generate the token;
determining, by the second component, a first client identifier associated with the first component;
determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response:
executing functionality responsive to the first call;
receiving, from a third component and by the second component, a second call, the token, and a second client certificate;
determining, by the second component, a second client identifier associated with the third component; and
determining, by the second component, that the second client identifier is absent from the manifest of the token, and in response:
transmitting an error to the third component.
2. The method of claim 1 , wherein executing functionality responsive to the first call at least partially comprises transmitting, from the second component and to a third component, a second call with the token.
3. The method of claim 1 , wherein the token is received by the first component from a third component.
4. The method of claim 1 , wherein the token comprises an open authentication (OAuth) client comprising an audience field populated with the manifest, and the first client certificate comprises a X.509 client certificate.
5. A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations for secure access token forwarding between components in cloud platforms, the operations comprising:
receiving, from a first component and by a second component in a cloud platform, a first call, a token, and a first client certificate; wherein the token provided to the first component in response to a request from the first component to a central identity and authentication service (IAS) of the cloud platform, and the first client certificate is provided during execution of a process to generate the token;
determining, by the second component, a first client identifier associated with the first component;
determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response:
executing functionality responsive to the first call;
receiving, from a third component and by the second component, a second call, the token, and a second client certificate;
determining, by the second component, a second client identifier associated with the third component; and
determining, by the second component, that the second client identifier is absent from the manifest of the token, and in response:
transmitting an error to the third component.
6. The computer-readable storage medium of claim 5 , wherein executing functionality responsive to the first call at least partially comprises transmitting, from the second component and to a third component, a second call with the token.
7. The computer-readable storage medium of claim 5 , wherein the token is received by the first component from a third component.
8. The computer-readable storage medium of claim 5 , wherein the token comprises an open authentication (OAuth) client comprising an audience field populated with the manifest, and the first client certificate comprises a X.509 client certificate.
9. A system, comprising:
a computing device; and
a computer-readable storage device coupled to the computing device and having instructions stored thereon which, when executed by the computing device, cause the computing device to perform operations for natural language explanations for secure access token forwarding between components in cloud platforms, the operations comprising:
receiving, from a first component and by a second component in a cloud platform, a first call, a token, and a first client certificate; wherein the token provided to the first component in response to a request from the first component to a central identity and authentication service (IAS) of the cloud platform, and the first client certificate is provided during execution of a process to generate the token;
determining, by the second component, a first client identifier associated with the first component;
determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response:
executing functionality responsive to the first call;
receiving, from a third component and by the second component, a second call, the token, and a second client certificate;
determining, by the second component, a second client identifier associated with the third component; and
determining, by the second component, that the second client identifier is absent from the manifest of the token, and in response:
transmitting an error to the third component.
10. The system of claim 9 , wherein executing functionality responsive to the first call at least partially comprises transmitting, from the second component and to a third component, a second call with the token.
11. The system of claim 9 , wherein the token is received by the first component from a third component.