Skip to content

Fix authenticated Ask OmniBioAI requests - #23

Merged
man4ish merged 1 commit into
mainfrom
fix/dev-hub-jwt-session-auth
Sep 27, 2026
Merged

man4ish merged 1 commit into
mainfrom
fix/dev-hub-jwt-session-auth

Conversation

@man4ish

@man4ish man4ish commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Authenticated Ask OmniBioAI requests now use the same-origin Studio access-token cookie for both query and stream calls, and the Dev Hub verifies JWT audience and issuer claims. This resolves protected RAG requests failing even when the Studio session is present, while requiring the configured token claims.

Validation:

  • pytest tests/test_auth.py tests/test_coverage_completion.py -q --no-cov — 33 passed
  • npm test -- --run src/api/client.test.ts — 18 passed
  • git diff --check — passed

@man4ish
man4ish merged commit 1ee9e75 into main Sep 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant