diff options
| author | omnom62 <omnom62@outlook.com> | 2026-10-03 16:44:59 +1000 |
|---|---|---|
| committer | omnom62 <omnom62@outlook.com> | 2026-10-03 16:44:59 +1000 |
| commit | e562acc5a2ac5efc16e1a9d623ca962225ee31f7 (patch) | |
| tree | a8d2366e0833cf4d8824ffe1ccaf2e35da033e2a | |
| parent | 6e9fe2c879895ade7c66b4ee199b0bac36f2b2e6 (diff) | |
| download | rest.vyos-t8989_auth_methods_rework.tar.gz rest.vyos-t8989_auth_methods_rework.zip | |
https: T8989: auth_methods AI comments fixedt8989_auth_methods_rework
| -rw-r--r-- | docs/vyos.rest.vyos_httpapi.rst | 23 | ||||
| -rw-r--r-- | plugins/httpapi/vyos.py | 17 | ||||
| -rw-r--r-- | tests/unit/test_httpapi_vyos.py | 24 |
3 files changed, 62 insertions, 2 deletions
diff --git a/docs/vyos.rest.vyos_httpapi.rst b/docs/vyos.rest.vyos_httpapi.rst index befe1a8..608339d 100644 --- a/docs/vyos.rest.vyos_httpapi.rst +++ b/docs/vyos.rest.vyos_httpapi.rst @@ -52,6 +52,7 @@ Parameters <div>env:ANSIBLE_HTTPAPI_API_KEY</div> <div>env:VYOS_API_KEY</div> <div>var: ansible_httpapi_api_key</div> + <div>var: ansible_vyos_api_key</div> </td> <td> <div>VyOS API key. Required for auth_method <code>key</code>, <code>header</code>, and <code>bearer</code>.</div> @@ -130,6 +131,28 @@ Parameters <tr> <td colspan="1"> <div class="ansibleOptionAnchor" id="parameter-"></div> + <b>oidc_timeout</b> + <a class="ansibleOptionLink" href="#parameter-" title="Permalink to this option"></a> + <div style="font-size: small"> + <span style="color: purple">integer</span> + </div> + </td> + <td> + <b>Default:</b><br/><div style="color: blue">10</div> + </td> + <td> + <div> ini entries: + <p>[httpapi]<br>oidc_timeout = 10</p> + </div> + <div>var: ansible_httpapi_oidc_timeout</div> + </td> + <td> + <div>Timeout, in seconds, for the token request made to the OIDC provider. An unavailable or stalled identity provider would otherwise hang the Ansible task indefinitely.</div> + </td> + </tr> + <tr> + <td colspan="1"> + <div class="ansibleOptionAnchor" id="parameter-"></div> <b>oidc_token_url</b> <a class="ansibleOptionLink" href="#parameter-" title="Permalink to this option"></a> <div style="font-size: small"> diff --git a/plugins/httpapi/vyos.py b/plugins/httpapi/vyos.py index 30088f3..e8121e7 100644 --- a/plugins/httpapi/vyos.py +++ b/plugins/httpapi/vyos.py @@ -25,6 +25,7 @@ options: type: str vars: - name: ansible_httpapi_api_key + - name: ansible_vyos_api_key env: - name: ANSIBLE_HTTPAPI_API_KEY - name: VYOS_API_KEY @@ -65,6 +66,18 @@ options: ini: - section: httpapi key: oidc_client_secret + oidc_timeout: + description: >- + Timeout, in seconds, for the token request made to the OIDC + provider. An unavailable or stalled identity provider would + otherwise hang the Ansible task indefinitely. + type: int + default: 10 + vars: + - name: ansible_httpapi_oidc_timeout + ini: + - section: httpapi + key: oidc_timeout """ import json @@ -180,12 +193,16 @@ class HttpApi(HttpApiBase): "client_secret": self.get_option("oidc_client_secret"), }, ) + timeout = self.get_option("oidc_timeout") + if timeout is None: + timeout = 10 try: response = open_url( token_url, data=body, headers={"Content-Type": "application/x-www-form-urlencoded"}, method="POST", + timeout=timeout, ) payload = json.loads(response.read()) except Exception as exc: diff --git a/tests/unit/test_httpapi_vyos.py b/tests/unit/test_httpapi_vyos.py index 9b0116b..4541c46 100644 --- a/tests/unit/test_httpapi_vyos.py +++ b/tests/unit/test_httpapi_vyos.py @@ -1,8 +1,8 @@ # -*- coding: utf-8 -*- """Unit tests for plugins/httpapi/vyos.py -Tests cover all three auth methods (key, header, bearer) and token -caching behaviour. The Ansible connection layer is mocked so no +Tests cover all five auth methods (key, header, bearer, mTLS, and OIDC) +and token caching behaviour. The Ansible connection layer is mocked so no real device is needed. """ from __future__ import absolute_import, division, print_function @@ -375,6 +375,26 @@ class TestSendRequestOidcMethod(unittest.TestCase): plugin.send_request("/retrieve", op="showConfig", path=[]) self.assertIn("OIDC token fetch failed", str(ctx.exception)) + def test_oidc_passes_configured_timeout(self): + """An unavailable or stalled IdP must not hang the task + indefinitely -- the timeout is passed through explicitly + rather than relying on open_url's own default.""" + plugin = self._plugin() + plugin.get_option = { + "auth_method": "oidc", + "oidc_token_url": "http://idp/token", + "oidc_client_id": "vyos-api", + "oidc_client_secret": "secret", + "oidc_timeout": 5, + }.get + with patch("ansible_collections.vyos.rest.plugins.httpapi.vyos.open_url") as mock_open_url: + mock_resp = MagicMock() + mock_resp.read.return_value = self._idp_response() + mock_open_url.return_value = mock_resp + plugin.connection.send.return_value = self._retrieve_response() + plugin.send_request("/retrieve", op="showConfig", path=[]) + self.assertEqual(mock_open_url.call_args[1]["timeout"], 5) + def test_oidc_raises_when_access_token_missing(self): plugin = self._plugin() with patch("ansible_collections.vyos.rest.plugins.httpapi.vyos.open_url") as mock_open_url: |
