Skip to content

Identifier gates, error disclosure, and authserver 0.2.0 alignment - #26

Merged
RobertoIskandarani merged 1 commit into
mainfrom
port/labs-sync
Oct 1, 2026
Merged

RobertoIskandarani merged 1 commit into
mainfrom
port/labs-sync

Conversation

@RobertoIskandarani

Copy link
Copy Markdown
Collaborator

Brings main up to the current development line ahead of the 0.2.0 cut. The [Unreleased] section of CHANGELOG.md is the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs.

What is in it

  • Identifier gating at construction. Resource and issuer identifiers are checked where the operator wrote them rather than at PRM derivation, so a misconfiguration surfaces at startup instead of from inside a 401 response path.
  • Disclosure. Internal error messages no longer reach the challenge or the JSON body. The RFC 6750 §3 shape is fixed and carries no exception text.
  • AS-hosted PRM. resource_metadata can point at a document the authorization server hosts.
  • authserver 0.2.0. access_denied and invalid_target are typed and excluded from the circuit breaker shared with introspection — five policy refusals used to open it, so an allowlist miss read as an AS outage. may_act is deprecated; the AS no longer issues it.
  • CI. A conformance case-body drift under an unchanged case id is now detected, and the pinned catalog checkout moves from an inline copy in each workflow to a shared script, so the 40-hex-SHA guard cannot be tightened in one and not the others. The catalog pin moves to 583a6d9.

One scrub

Two comments in the test suite carried an internal tracker id (AuthplaneMcpAuthMiddlewareTests.cs and AuthplaneErrorsTests.cs). Both are reworded here with no change to what they say about the code.

Nothing else on main had to be preserved against the development line: the action pins match on both sides, <Version> is 0.1.0 on both, and the workflow files where main had content the development line lacks are the inline catalog checkout that the shared script now replaces.

Verification

dotnet format, build and test green locally — on net10.0 only. No net8.0 runtime is installed on the machine that ran them, so that target framework is covered by CI alone. Conformance suites driven against the pinned catalog 583a6d9, which is what CI reads.

Brings main up to the current development line ahead of the 0.2.0 cut. The
CHANGELOG's [Unreleased] section is the authoritative list of what changed for
a caller; this body covers the mechanics a reviewer needs.

- Resource and issuer identifiers are gated at construction rather than at PRM
  derivation, so a misconfiguration surfaces at startup instead of from inside
  a 401 response path.
- Internal error messages no longer reach the challenge or the JSON body; the
  RFC 6750 §3 shape is fixed and carries no exception text.
- resource_metadata can point at an AS-hosted PRM document.
- authserver 0.2.0: access_denied and invalid_target are typed and excluded
  from the circuit breaker shared with introspection, where five policy
  refusals used to open it. may_act is deprecated — the AS no longer issues it.
- CI detects a conformance case-body drift under an unchanged case id, and the
  pinned catalog checkout moves from an inline copy in each workflow to a
  shared script, so the 40-hex-SHA guard cannot be tightened in one and not
  the others. The catalog pin moves to 583a6d9.

Two comments in the test suite carried an internal tracker id; both are
reworded here, with no change to what they say about the code.
@RobertoIskandarani
RobertoIskandarani requested a review from a team as a code owner September 29, 2026 17:52
@RobertoIskandarani
RobertoIskandarani merged commit 835a0bc into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants