Skip to content

Add multi-key JWKS rotation for LTI 1.3 signing keys#8056

Open
donny-wong wants to merge 4 commits into
MarkUsProject:masterfrom
donny-wong:quercus_integration_lti_jwks_key_rotation
Open

Add multi-key JWKS rotation for LTI 1.3 signing keys#8056
donny-wong wants to merge 4 commits into
MarkUsProject:masterfrom
donny-wong:quercus_integration_lti_jwks_key_rotation

Conversation

@donny-wong

@donny-wong donny-wong commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Proposed Changes

(Describe your changes here. Also describe the motivation for your changes: what problem do they solve, or how do they improve the application or codebase? If this pull request fixes an open issue, use a keyword to link this pull request to the issue.)

Summary

MarkUs signs LTI 1.3 client_credentials assertions with a single RSA key and publishes exactly one key at /lti_deployments/public_jwk. Rotating it is therefore a hard swap — the outgoing key leaves the published JWKS the moment it stops signing, so assertions already in flight fail verification.

This adds multi-key support with an overlap window, so keys can be rotated without disrupting grade passback (AGS) or roster sync (NRPS).

What changed

LtiKeyStore (new) manages a directory of timestamped PEMs:

  • The newest key is the current signer (overridable via Settings.lti.rotation.current_key).
  • public_jwks publishes every key present, so a retired key still verifies until pruned.
  • A key is retired when its successor is created. prune! removes keys retired longer ago than the overlap window, and never removes the current signer.
    LtiClient#get_oauth_token and LtiDeploymentsController#public_jwk now both go through the store, so signing and publication share one source of truth.

LtiKeyMaintenanceJob runs daily via resque-scheduler when enabled: rotates only if the current key is past max_age_days, prunes keys past overlap_days. Both are idempotent.

Rake tasks remain for manual use, including compromise response: markus:lti_key, markus:rotate_if_due, markus:prune_keys.

Screenshots of your changes (if applicable)

Type of Change

(Write an X or a brief description next to the type or types that best describe your changes.)

Type Applies?
🚨 Breaking change (fix or feature that would cause existing functionality to change)
New feature (non-breaking change that adds functionality) x
🐛 Bug fix (non-breaking change that fixes an issue)
🎨 User interface change (change to user interface; provide screenshots)
♻️ Refactoring (internal change to codebase, without changing functionality)
🚦 Test update (change that only adds or modifies tests)
📦 Dependency update (change that updates a dependency)
📖 Documentation update (change that updates documentation)
🔧 Internal (change that only affects developers or continuous integration)

Checklist

(Complete each of the following items for your pull request. Indicate that you have completed an item by changing the [ ] into a [x] in the raw text, or by clicking on the checkbox in the rendered description on GitHub.)

Before opening your pull request:

  • I have performed a self-review of my changes.
    • Check that all changed files included in this pull request are intentional changes.
    • Check that all changes are relevant to the purpose of this pull request, as described above.
  • I have added tests for my changes, if applicable.
    • This is required for all bug fixes and new features.
  • I have updated the project documentation, if applicable.
    • This is required for new features.
  • If this is my first contribution, I have added myself to the list of contributors.

After opening your pull request:

  • I have updated the project Changelog (this is required for all changes).
  • I have verified that the pre-commit.ci checks have passed.
  • I have verified that the CI tests have passed.
  • I have reviewed the test coverage changes reported by Coveralls.
  • I have requested a review from a project maintainer.

Questions and Comments

(Include any questions or comments you have regarding your changes.)

@donny-wong
donny-wong force-pushed the quercus_integration_lti_jwks_key_rotation branch from 0757c80 to fa67474 Compare July 13, 2026 23:11
@coveralls

coveralls commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 29976878820

Coverage increased (+0.04%) to 90.45%

Details

  • Coverage increased (+0.04%) from the base build.
  • Patch coverage: 6 uncovered changes across 1 file (273 of 279 lines covered, 97.85%).
  • No coverage regressions found.

Uncovered Changes

File Changed Covered %
config/initializers/config.rb 6 0 0.0%
Total (12 files) 279 273 97.85%

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 51562
Covered Lines: 47654
Line Coverage: 92.42%
Relevant Branches: 2470
Covered Branches: 1218
Branch Coverage: 49.31%
Branches in Coverage %: Yes
Coverage Strength: 127.22 hits per line

💛 - Coveralls

@donny-wong
donny-wong requested a review from Naragod July 14, 2026 00:15

@Naragod Naragod left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey Donny, this is completely new to me, which took me a while to review with the assistance of Claude. I left a few comments based on my understanding of the code and what we are trying to do.

Comment thread app/lib/lti_key_store.rb
Comment thread app/lib/lti_key_store.rb
@donny-wong
donny-wong force-pushed the quercus_integration_lti_jwks_key_rotation branch from 2dd6d6c to 0cfd0bc Compare July 23, 2026 03:23
@donny-wong
donny-wong requested a review from Naragod July 23, 2026 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants