Skip to content

Resource gates, error taxonomy, and authserver 0.2.0 alignment - #32

Merged
RobertoIskandarani merged 1 commit into
mainfrom
port/labs-sync
Oct 1, 2026
Merged

RobertoIskandarani merged 1 commit into
mainfrom
port/labs-sync

Conversation

@RobertoIskandarani

Copy link
Copy Markdown
Contributor

Brings main up to the current development line ahead of the 0.4.0 cut. The [Unreleased] section of CHANGELOG.md is the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs.

What is in it

  • The no-credentials response drops an invented error code. RFC 6750 §3 describes a bare WWW-Authenticate challenge for a request that presents no credentials at all — the code was not one any RFC defines, and a client branching on it was branching on something we made up.
  • Identifier gating. Resource and issuer identifiers are checked where they are consumed, not only where the PRM URL is derived, so a misconfiguration surfaces at startup rather than from inside a 401 response path.
  • Disclosure. Internal error messages stay out of the WWW-Authenticate challenge.
  • AS-hosted PRM. resource_metadata can point at a document the authorization server hosts.
  • authserver 0.2.0. access_denied and invalid_target are typed and excluded from the circuit breaker shared with introspection — five policy refusals used to open it, so an allowlist miss read as an AS outage. may_act is deprecated; the AS no longer issues it.
  • Conformance catalog pin moves to 583a6d9, and the shared fetch script gains an overridable destination so the drift job and CI can both use it.

Nothing is carried forward

Unlike the sibling ports in this round, nothing on main had to be preserved against the development line: the action pins match on both sides, there is no version manifest to drift (the tags are the version), and the only file where main had content the development line lacked was fetch-conformance-catalog.sh, where it was the older wording of the same comments.

Verification

go build, go vet, go test and gofmt green locally across all four modules, with the conformance suites driven against the pinned catalog 583a6d9, which is what CI reads.

Note for the release: release.yml tags all five refs together — core/, mcp/, http/, mark3labs/ and the root.

Brings main up to the current development line ahead of the 0.4.0 cut. The
CHANGELOG's [Unreleased] section is the authoritative list of what changed for
a caller; this body covers the mechanics a reviewer needs.

- The no-credentials response no longer carries an error code that no RFC
  defines: RFC 6750 §3 describes a bare challenge for a request that presents
  no credentials, and an invented code is what a client would branch on.
- Resource and issuer identifiers are gated where they are consumed, not only
  where the PRM URL is derived.
- Internal error messages stay out of the WWW-Authenticate challenge.
- resource_metadata can point at an AS-hosted PRM document.
- authserver 0.2.0: access_denied and invalid_target are typed and excluded
  from the circuit breaker shared with introspection. may_act is deprecated —
  the AS no longer issues it.
- The conformance catalog pin moves to 583a6d9, and the shared fetch script
  gains an overridable destination so the drift job and CI can use it alike.
@RobertoIskandarani
RobertoIskandarani requested a review from a team as a code owner September 29, 2026 17:51
Comment thread http/pkg/authplanehttp/adapter.go Dismissed
@RobertoIskandarani
RobertoIskandarani merged commit 2028b76 into main Oct 1, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants