Identifier gates, error disclosure, and authserver 0.2.0 alignment - #40
Open
RobertoIskandarani wants to merge 1 commit into
Open
RobertoIskandarani wants to merge 1 commit into
RobertoIskandarani wants to merge 1 commit into
Conversation
Brings main up to the current development line. The CHANGELOG's [Unreleased] section is the authoritative list; the themes are: - A resource identifier must carry an authority at construction, and userinfo is rejected there rather than at derivation. - Internal error messages no longer reach the challenge or the response body, on core, mcp and spring alike. - resource_metadata can point at an AS-hosted PRM document, with the identifier's userinfo and fragment gates applied to the override. - authserver 0.2.0: access_denied and invalid_target are typed and kept out of the circuit breaker; VerifiedClaims.mayAct is deprecated. An interrupted revocation check restores the interrupt flag. - CI detects a conformance case-body drift under an unchanged case id, and the catalog checkout is a shared script rather than an inline copy per workflow. Two files keep what main already had rather than taking the development line's copy: the POM versions stay on the 0.2.1-SNAPSHOT line main was bumped to, and publish-maven.yml keeps its conformance catalog checkout — converted to the shared script the other workflows now use, since its `-P release verify` re-runs the alignment tests before the deploy.
muralx
approved these changes
Sep 29, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings
mainup to the current development line ahead of the 0.3.0 cut. The[Unreleased]section ofCHANGELOG.mdis the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs.What is in it
core,mcpandspring.resource_metadatacan point at a document the authorization server hosts, with the identifier’s userinfo and fragment gates applied to the override.access_deniedandinvalid_targetare typed and excluded from the circuit breaker shared with introspection — five policy refusals used to open it.VerifiedClaims.mayAct()is deprecated; the AS no longer issuesmay_act. An interrupted revocation check restores the interrupt flag instead of swallowing it.Two deliberate carry-forwards
Both are places where this branch keeps what
mainalready had rather than taking the development line’s copy:0.2.1-SNAPSHOT, the linemainwas bumped to after 0.2.0. The development line carries1.0.0-SNAPSHOT, which was never the released line and would have put a version onmainthat no release ever produced.publish-maven.ymlkeeps its conformance catalog checkout, which the development line does not have at all. Converted to the shared script the other workflows now use. This one is load-bearing:-P release verifyre-runs the full suite as the last gate before the Central deploy, and the alignment tests read the catalog throughCONFORMANCE_CATALOG_PATH— without it the release job fails at the point where it is most expensive to fail.Verification
mvn verifygreen locally, with the conformance suites driven against the pinned catalog583a6d9, which is what CI reads.