Resource gates, error taxonomy, and authserver 0.2.0 alignment - #32
Merged
Merged
Conversation
Brings main up to the current development line ahead of the 0.4.0 cut. The CHANGELOG's [Unreleased] section is the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs. - The no-credentials response no longer carries an error code that no RFC defines: RFC 6750 §3 describes a bare challenge for a request that presents no credentials, and an invented code is what a client would branch on. - Resource and issuer identifiers are gated where they are consumed, not only where the PRM URL is derived. - Internal error messages stay out of the WWW-Authenticate challenge. - resource_metadata can point at an AS-hosted PRM document. - authserver 0.2.0: access_denied and invalid_target are typed and excluded from the circuit breaker shared with introspection. may_act is deprecated — the AS no longer issues it. - The conformance catalog pin moves to 583a6d9, and the shared fetch script gains an overridable destination so the drift job and CI can use it alike.
muralx
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings
mainup to the current development line ahead of the 0.4.0 cut. The[Unreleased]section ofCHANGELOG.mdis the authoritative list of what changed for a caller; this body covers the mechanics a reviewer needs.What is in it
WWW-Authenticatechallenge for a request that presents no credentials at all — the code was not one any RFC defines, and a client branching on it was branching on something we made up.WWW-Authenticatechallenge.resource_metadatacan point at a document the authorization server hosts.access_deniedandinvalid_targetare typed and excluded from the circuit breaker shared with introspection — five policy refusals used to open it, so an allowlist miss read as an AS outage.may_actis deprecated; the AS no longer issues it.583a6d9, and the shared fetch script gains an overridable destination so the drift job and CI can both use it.Nothing is carried forward
Unlike the sibling ports in this round, nothing on
mainhad to be preserved against the development line: the action pins match on both sides, there is no version manifest to drift (the tags are the version), and the only file wheremainhad content the development line lacked wasfetch-conformance-catalog.sh, where it was the older wording of the same comments.Verification
go build,go vet,go testandgofmtgreen locally across all four modules, with the conformance suites driven against the pinned catalog583a6d9, which is what CI reads.Note for the release:
release.ymltags all five refs together —core/,mcp/,http/,mark3labs/and the root.