summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-10-03 16:44:59 +1000
committeromnom62 <omnom62@outlook.com>2026-10-03 16:44:59 +1000
commite562acc5a2ac5efc16e1a9d623ca962225ee31f7 (patch)
treea8d2366e0833cf4d8824ffe1ccaf2e35da033e2a
parent6e9fe2c879895ade7c66b4ee199b0bac36f2b2e6 (diff)
downloadrest.vyos-t8989_auth_methods_rework.tar.gz
rest.vyos-t8989_auth_methods_rework.zip
https: T8989: auth_methods AI comments fixedt8989_auth_methods_rework
-rw-r--r--docs/vyos.rest.vyos_httpapi.rst23
-rw-r--r--plugins/httpapi/vyos.py17
-rw-r--r--tests/unit/test_httpapi_vyos.py24
3 files changed, 62 insertions, 2 deletions
diff --git a/docs/vyos.rest.vyos_httpapi.rst b/docs/vyos.rest.vyos_httpapi.rst
index befe1a8..608339d 100644
--- a/docs/vyos.rest.vyos_httpapi.rst
+++ b/docs/vyos.rest.vyos_httpapi.rst
@@ -52,6 +52,7 @@ Parameters
<div>env:ANSIBLE_HTTPAPI_API_KEY</div>
<div>env:VYOS_API_KEY</div>
<div>var: ansible_httpapi_api_key</div>
+ <div>var: ansible_vyos_api_key</div>
</td>
<td>
<div>VyOS API key. Required for auth_method <code>key</code>, <code>header</code>, and <code>bearer</code>.</div>
@@ -130,6 +131,28 @@ Parameters
<tr>
<td colspan="1">
<div class="ansibleOptionAnchor" id="parameter-"></div>
+ <b>oidc_timeout</b>
+ <a class="ansibleOptionLink" href="#parameter-" title="Permalink to this option"></a>
+ <div style="font-size: small">
+ <span style="color: purple">integer</span>
+ </div>
+ </td>
+ <td>
+ <b>Default:</b><br/><div style="color: blue">10</div>
+ </td>
+ <td>
+ <div> ini entries:
+ <p>[httpapi]<br>oidc_timeout = 10</p>
+ </div>
+ <div>var: ansible_httpapi_oidc_timeout</div>
+ </td>
+ <td>
+ <div>Timeout, in seconds, for the token request made to the OIDC provider. An unavailable or stalled identity provider would otherwise hang the Ansible task indefinitely.</div>
+ </td>
+ </tr>
+ <tr>
+ <td colspan="1">
+ <div class="ansibleOptionAnchor" id="parameter-"></div>
<b>oidc_token_url</b>
<a class="ansibleOptionLink" href="#parameter-" title="Permalink to this option"></a>
<div style="font-size: small">
diff --git a/plugins/httpapi/vyos.py b/plugins/httpapi/vyos.py
index 30088f3..e8121e7 100644
--- a/plugins/httpapi/vyos.py
+++ b/plugins/httpapi/vyos.py
@@ -25,6 +25,7 @@ options:
type: str
vars:
- name: ansible_httpapi_api_key
+ - name: ansible_vyos_api_key
env:
- name: ANSIBLE_HTTPAPI_API_KEY
- name: VYOS_API_KEY
@@ -65,6 +66,18 @@ options:
ini:
- section: httpapi
key: oidc_client_secret
+ oidc_timeout:
+ description: >-
+ Timeout, in seconds, for the token request made to the OIDC
+ provider. An unavailable or stalled identity provider would
+ otherwise hang the Ansible task indefinitely.
+ type: int
+ default: 10
+ vars:
+ - name: ansible_httpapi_oidc_timeout
+ ini:
+ - section: httpapi
+ key: oidc_timeout
"""
import json
@@ -180,12 +193,16 @@ class HttpApi(HttpApiBase):
"client_secret": self.get_option("oidc_client_secret"),
},
)
+ timeout = self.get_option("oidc_timeout")
+ if timeout is None:
+ timeout = 10
try:
response = open_url(
token_url,
data=body,
headers={"Content-Type": "application/x-www-form-urlencoded"},
method="POST",
+ timeout=timeout,
)
payload = json.loads(response.read())
except Exception as exc:
diff --git a/tests/unit/test_httpapi_vyos.py b/tests/unit/test_httpapi_vyos.py
index 9b0116b..4541c46 100644
--- a/tests/unit/test_httpapi_vyos.py
+++ b/tests/unit/test_httpapi_vyos.py
@@ -1,8 +1,8 @@
# -*- coding: utf-8 -*-
"""Unit tests for plugins/httpapi/vyos.py
-Tests cover all three auth methods (key, header, bearer) and token
-caching behaviour. The Ansible connection layer is mocked so no
+Tests cover all five auth methods (key, header, bearer, mTLS, and OIDC)
+and token caching behaviour. The Ansible connection layer is mocked so no
real device is needed.
"""
from __future__ import absolute_import, division, print_function
@@ -375,6 +375,26 @@ class TestSendRequestOidcMethod(unittest.TestCase):
plugin.send_request("/retrieve", op="showConfig", path=[])
self.assertIn("OIDC token fetch failed", str(ctx.exception))
+ def test_oidc_passes_configured_timeout(self):
+ """An unavailable or stalled IdP must not hang the task
+ indefinitely -- the timeout is passed through explicitly
+ rather than relying on open_url's own default."""
+ plugin = self._plugin()
+ plugin.get_option = {
+ "auth_method": "oidc",
+ "oidc_token_url": "http://idp/token",
+ "oidc_client_id": "vyos-api",
+ "oidc_client_secret": "secret",
+ "oidc_timeout": 5,
+ }.get
+ with patch("ansible_collections.vyos.rest.plugins.httpapi.vyos.open_url") as mock_open_url:
+ mock_resp = MagicMock()
+ mock_resp.read.return_value = self._idp_response()
+ mock_open_url.return_value = mock_resp
+ plugin.connection.send.return_value = self._retrieve_response()
+ plugin.send_request("/retrieve", op="showConfig", path=[])
+ self.assertEqual(mock_open_url.call_args[1]["timeout"], 5)
+
def test_oidc_raises_when_access_token_missing(self):
plugin = self._plugin()
with patch("ansible_collections.vyos.rest.plugins.httpapi.vyos.open_url") as mock_open_url: