Skip to content

Identifier gates, error disclosure, and authserver 0.2.0 alignment - #40

Open
RobertoIskandarani wants to merge 1 commit into
mainfrom
port/labs-sync
Open

RobertoIskandarani wants to merge 1 commit into
mainfrom
port/labs-sync

Conversation

@RobertoIskandarani

Copy link
Copy Markdown
Collaborator

Brings main up to the current development line ahead of the 0.3.0 cut. The [Unreleased] section of CHANGELOG.md is the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs.

What is in it

  • Identifier gating at construction. A resource identifier must carry an authority, and userinfo is rejected, where the operator wrote it rather than at PRM derivation — i.e. at startup instead of from inside a 401 response path.
  • Disclosure. Internal error messages no longer reach the challenge or the response body, across core, mcp and spring.
  • AS-hosted PRM. resource_metadata can point at a document the authorization server hosts, with the identifier’s userinfo and fragment gates applied to the override.
  • authserver 0.2.0. access_denied and invalid_target are typed and excluded from the circuit breaker shared with introspection — five policy refusals used to open it. VerifiedClaims.mayAct() is deprecated; the AS no longer issues may_act. An interrupted revocation check restores the interrupt flag instead of swallowing it.
  • CI. A conformance case-body drift under an unchanged case id is now detected, and the pinned catalog checkout is a shared script rather than an inline copy per workflow, so the 40-hex-SHA guard cannot be tightened in one and not the others.

Two deliberate carry-forwards

Both are places where this branch keeps what main already had rather than taking the development line’s copy:

  1. POM versions stay on 0.2.1-SNAPSHOT, the line main was bumped to after 0.2.0. The development line carries 1.0.0-SNAPSHOT, which was never the released line and would have put a version on main that no release ever produced.
  2. publish-maven.yml keeps its conformance catalog checkout, which the development line does not have at all. Converted to the shared script the other workflows now use. This one is load-bearing: -P release verify re-runs the full suite as the last gate before the Central deploy, and the alignment tests read the catalog through CONFORMANCE_CATALOG_PATH — without it the release job fails at the point where it is most expensive to fail.

Verification

mvn verify green locally, with the conformance suites driven against the pinned catalog 583a6d9, which is what CI reads.

Brings main up to the current development line. The CHANGELOG's
[Unreleased] section is the authoritative list; the themes are:

- A resource identifier must carry an authority at construction, and
  userinfo is rejected there rather than at derivation.
- Internal error messages no longer reach the challenge or the response
  body, on core, mcp and spring alike.
- resource_metadata can point at an AS-hosted PRM document, with the
  identifier's userinfo and fragment gates applied to the override.
- authserver 0.2.0: access_denied and invalid_target are typed and kept
  out of the circuit breaker; VerifiedClaims.mayAct is deprecated. An
  interrupted revocation check restores the interrupt flag.
- CI detects a conformance case-body drift under an unchanged case id,
  and the catalog checkout is a shared script rather than an inline copy
  per workflow.

Two files keep what main already had rather than taking the development
line's copy: the POM versions stay on the 0.2.1-SNAPSHOT line main was
bumped to, and publish-maven.yml keeps its conformance catalog checkout —
converted to the shared script the other workflows now use, since its
`-P release verify` re-runs the alignment tests before the deploy.
@RobertoIskandarani
RobertoIskandarani requested a review from a team as a code owner September 28, 2026 22:09

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants