feat(service): add bearer authorization passthrough - #3796
derekwaynecarr wants to merge 5 commits into
Conversation
|
/ok to test 1926927 |
Findings
Implementation assessmentThe design otherwise looks good: • Omitted, legacy, and unknown stored values fail closed to strip. |
|
Label |
|
/ok to test 1926927 |
Follow-Up NeededThanks @mrunalp. I checked your points against the current head: the independent code review found no additional implementation blocker, but this feature still has no linked accepted issue, the stable Rust Action required: @derekwaynecarr, please link the accepted issue in a Related Issue section and add the required SDK compatibility notice and migration guidance (or preserve source compatibility). Please also fix the checklist syntax while updating the PR body. Gator applied If the PR author or a maintainer does not respond within 48 business hours, this may be closed. Weekend hours do not count toward the TTL. Gator metadata
|
1926927 to
3bc9828
Compare
|
/ok to test 3bc9828 |
|
/ok to test 3bc9828 |
FYI @derekwaynecarr I'm fixing you're not being able to trigger the copy bot, it will be working soon. |
3bc9828 to
2d694c3
Compare
|
/ok to test 2d694c3 |
Signed-off-by: Derek Carr <decarr@redhat.com>
Signed-off-by: Derek Carr <decarr@redhat.com>
Signed-off-by: Derek Carr <decarr@redhat.com>
Signed-off-by: Derek Carr <decarr@redhat.com>
Signed-off-by: Derek Carr <decarr@redhat.com>
2d694c3 to
af2240e
Compare
|
/ok to test af2240e |
|
from my clanker after looking at your change + designing around it in OCE: Thanks, Derek. We are planning to use this path for dedicated Codex Agents in OpenClaw Enterprise. Could we add an end-to-end WebSocket case for bearer passthrough before this lands? At It would be useful to exercise a real upgrade through the exposed service, verify that the application accepts a valid bearer and exchanges frames, and verify that the application rejects a missing or incorrect bearer. A default-strip case would also confirm that a credential is not forwarded unless the service opts in. We will separately qualify OCE's TLS, authority and revision lifecycle around the route. This is a coverage request for the intended WebSocket use case, not a claim that the current implementation is broken. We are testing against the current PR head locally as well. |
Summary
Allow an exposed sandbox service to opt into forwarding an application bearer
credential from the incoming HTTP or WebSocket request to the loopback service.
The default continues to strip
Authorization, and the control-plane listener,certificate, and authentication model remain unchanged in this iteration.
The motivating integration is an authenticated Codex App Server reached through
an OpenShell service URL. Codex validates the bearer capability during the
WebSocket handshake. OpenShell routes the request but does not authenticate the
application credential.
The Codex WebSocket transport is currently documented as experimental and
unsupported for production workloads. This feature remains application-neutral;
the Codex fixture is interoperability coverage, not a production-support claim.
Related Issue
#3851
Testing
mise run pre-commitpassesChecklist