Document extracting authentication from custom metadata - #417
Closed
Adrastopoulos wants to merge 1 commit into
Closed
Document extracting authentication from custom metadata#417Adrastopoulos wants to merge 1 commit into
Adrastopoulos wants to merge 1 commit into
Conversation
GrpcSecurity accepts arbitrary GrpcAuthenticationExtractor instances, but the reference docs only covered the built-in Authorization header mechanisms, so credentials carried in other metadata entries had no documented path. The composition rules were also untested: extractors are sorted by @order and the first non-null Authentication wins. Document authenticationExtractor() with a worked example and add tests covering extractor ordering and first-non-null resolution. Signed-off-by: Gabriel Hall <gabriel.hall@cox.net>
Adrastopoulos
force-pushed
the
gabriel/custom-credentials-docs
branch
from
July 29, 2026 08:10
922bbb2 to
bbbeaf2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
GrpcSecurity.authenticationExtractor(...)is public and accepts anyGrpcAuthenticationExtractor, but the reference docs only cover the built-in mechanisms, all of which read theAuthorizationmetadata entry. Credentials that arrive in another metadata key (a session token, an API key header, a gateway-issued principal) have no documented path, even though the extension point already supports them.Two behaviours of that extension point were also untested:
AnnotationAwareOrderComparator, so@Ordercontrols precedence.CompositeAuthenticationExtractorreturns the first non-nullAuthentication, so a custom extractor composes with the built-in ones rather than replacing them.This documents
authenticationExtractor()with a worked example and addsGrpcSecurityAuthenticationExtractorTests, which drives calls through the interceptor built byGrpcSecurityand asserts both behaviours.No main source changes.
Verified with
./mvnw clean installon JDK 25 (144 tests, 0 failures). Code formatted withspring-javaformat:applyper CONTRIBUTING.