Skip to content

Wallet-signed managed upload authorization - #8

Open
thedanielmark wants to merge 2 commits into
mainfrom
feat/managed-upload-wallet-auth
Open

thedanielmark wants to merge 2 commits into
mainfrom
feat/managed-upload-wallet-auth

Conversation

@thedanielmark

Copy link
Copy Markdown
Member

Summary

  • Request POST /api/registration-metadata/challenge before managed metadata upload.
  • Sign the challenge with the registration wallet and send Authorization: AgentoryUpload v1 challenge="…" signature="0x…".
  • Honor MANAGED_UPLOAD_AUTH_DISABLED / AGENTORY_MANAGED_UPLOAD_AUTH_DISABLED for APIs that skip auth.

Dependency

Requires AxLabs/agentory#88.

…a uploads.

Request a server challenge, sign with the registration wallet, and send the authorization header before POSTing registration metadata. Honor MANAGED_UPLOAD_AUTH_DISABLED for local APIs that skip server auth.
…ests.

Resolve AGENTORY_API_BASE_URL before signer checks, harden challenge/signing error handling, and add focused wallet authorization tests without weakening production auth requirements.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant