Skip to content

Add agent-secret endpoint to SlaveComputer#26017

Open
adhamahmad wants to merge 3 commits intojenkinsci:masterfrom
adhamahmad:closes#16537
Open

Add agent-secret endpoint to SlaveComputer#26017
adhamahmad wants to merge 3 commits intojenkinsci:masterfrom
adhamahmad:closes#16537

Conversation

@adhamahmad
Copy link
Contributor

Introduces a new /agent-secret web method in SlaveComputer to expose the agent's JNLP MAC. Adds corresponding tests to verify access control and response correctness for users with and without the required permission.

Fixes #16537

Testing done

  • Added two unit tests in SlaveComputerTest to cover both cases: successful scenario and unsuccessful scenario, by simulating two users: one with the required permissions and the other without.
  • Tested manually using curl to verify the behavior in both successful and unsuccessful scenarios.

Proposed changelog entries

  • Add a new API in SlaveComputer to obtain the secret required for remote launch of an agent.

Proposed changelog category

/label rfe

Proposed upgrade guidelines

N/A

Submitter checklist

  • The issue, if it exists, is well-described.
  • The changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developers, depending on the change) and are in the imperative mood (see examples). Fill in the Proposed upgrade guidelines section only if there are breaking changes or changes that may require extra steps from users during upgrade.
  • There is automated testing or an explanation as to why this change has no tests.
  • New public classes, fields, and methods are annotated with @Restricted or have @since TODO Javadocs, as appropriate.
  • New deprecations are annotated with @Deprecated(since = "TODO") or @Deprecated(forRemoval = true, since = "TODO"), if applicable.
  • UI changes do not introduce regressions when enforcing the current default rules of Content Security Policy Plugin. In particular, new or substantially changed JavaScript is not defined inline and does not call eval to ease future introduction of Content Security Policy (CSP) directives (see documentation).
  • For dependency updates, there are links to external changelogs and, if possible, full differentials.
  • For new APIs and extension points, there is a link to at least one consumer.

Desired reviewers

@mention

Before the changes are marked as ready-for-merge:

Maintainer checklist

  • There are at least two (2) approvals for the pull request and no outstanding requests for change.
  • Conversations in the pull request are over, or it is explicit that a reviewer is not blocking the change.
  • Changelog entries in the pull request title and/or Proposed changelog entries are accurate, human-readable, and in the imperative mood.
  • Proper changelog labels are set so that the changelog can be generated automatically.
  • If the change needs additional upgrade steps from users, the upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the pull request title (see example).
  • If it would make sense to backport the change to LTS, be a Bug or Improvement, and either the issue or pull request must be labeled as lts-candidate to be considered.

@comment-ops-bot comment-ops-bot bot added the rfe For changelog: Minor enhancement. use `major-rfe` for changes to be highlighted label Dec 29, 2025
@adhamahmad
Copy link
Contributor Author

Usage Example:

curl -u user:USER_TOKEN http://localhost:8080/computer/<agnet-name>/agent-secret

@adhamahmad
Copy link
Contributor Author

@jenkinsci/core-pr-reviewers

Introduces a new /agent-secret web method in SlaveComputer to expose the agent's JNLP MAC. Adds corresponding tests to verify access control and response correctness for users with and without the required permission.
Added Jenkins.READ permission for 'user-without-connect' in SlaveComputerTest to ensure proper authorization setup during testing.
Ensures the web client logs in as userWithoutConnect before attempting to access the agent-secret endpoint.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rfe For changelog: Minor enhancement. use `major-rfe` for changes to be highlighted

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[JENKINS-73735] Rest api to obtain the secret required for remote launch of an agent

2 participants