Identifier gates, error disclosure, and authserver 0.2.0 alignment - #26
Merged
Merged
Conversation
Brings main up to the current development line ahead of the 0.2.0 cut. The CHANGELOG's [Unreleased] section is the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs. - Resource and issuer identifiers are gated at construction rather than at PRM derivation, so a misconfiguration surfaces at startup instead of from inside a 401 response path. - Internal error messages no longer reach the challenge or the JSON body; the RFC 6750 §3 shape is fixed and carries no exception text. - resource_metadata can point at an AS-hosted PRM document. - authserver 0.2.0: access_denied and invalid_target are typed and excluded from the circuit breaker shared with introspection, where five policy refusals used to open it. may_act is deprecated — the AS no longer issues it. - CI detects a conformance case-body drift under an unchanged case id, and the pinned catalog checkout moves from an inline copy in each workflow to a shared script, so the 40-hex-SHA guard cannot be tightened in one and not the others. The catalog pin moves to 583a6d9. Two comments in the test suite carried an internal tracker id; both are reworded here, with no change to what they say about the code.
muralx
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings
mainup to the current development line ahead of the 0.2.0 cut. The[Unreleased]section ofCHANGELOG.mdis the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs.What is in it
resource_metadatacan point at a document the authorization server hosts.access_deniedandinvalid_targetare typed and excluded from the circuit breaker shared with introspection — five policy refusals used to open it, so an allowlist miss read as an AS outage.may_actis deprecated; the AS no longer issues it.583a6d9.One scrub
Two comments in the test suite carried an internal tracker id (
AuthplaneMcpAuthMiddlewareTests.csandAuthplaneErrorsTests.cs). Both are reworded here with no change to what they say about the code.Nothing else on
mainhad to be preserved against the development line: the action pins match on both sides,<Version>is0.1.0on both, and the workflow files wheremainhad content the development line lacks are the inline catalog checkout that the shared script now replaces.Verification
dotnet format,buildandtestgreen locally — onnet10.0only. Nonet8.0runtime is installed on the machine that ran them, so that target framework is covered by CI alone. Conformance suites driven against the pinned catalog583a6d9, which is what CI reads.