Conversation
Select the most-specific grant independently for each protected header, preserving each credential's issuer, audience and cache identity. Resolve all selected grants before rewriting the request, replace agent-supplied header copies, and fail closed on collisions or acquisition failures. Allow distinct-header compositions in gateway validation and redact raw issuer errors. Cover independent cache entries, atomic TLS relay failure, header replacement and concurrent request isolation; document the profile contract. Fixes #3320 Signed-off-by: Shiju <shiju@nvidia.com>
Use if-let for a grant result whose error payload is deliberately ignored, and name the empty query map type in the regression fixture. Preserve grant acquisition, failure redaction and request atomicity. Update the token-exchange failure test to require the sanitized error instead of raw issuer text. Signed-off-by: Shiju <shiju@nvidia.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-4047.docs.buildwithfern.com/openshell |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
The independent code review found no blocking findings in the multiple-token implementation. The provider docs explain header selection, independent caching, header replacement, and fail-closed behavior; runtime E2E testing is now running on this head.
Blocking findings:
- No blocking findings remain.
Carried findings:
- None.
Non-blocking suggestions:
- None.
Gator metadata
- Validation: Implements accepted issue #3320 for independent dynamic credential injection on one admitted request.
- Docs: Updated Fern provider-profile reference; no new navigation needed.
- Checks: Branch Checks, Helm Lint, Trivy Changes, DCO, and vouch checks passed on this head. Required E2E remains pending.
- E2E: Applied
test:e2e; followed E2E Label Help and reran Branch E2E Checks run 36860996045, attempt 2 confirmed running on the current head. The mirror is current. - Head SHA:
decdfcb84891f34a3bb8141352d76db1484292b6 - Base SHA:
021400be8af471f8669369e679de3e18cf0bd672 - Merge base SHA:
5acaaba19281cb6b30171afeb8602ce83edd9e45 - Patch ID:
15fcbc96cd95b80b2f51b59a5e0d1eabb48f2499 - Gator payload:
10 - Review mode:
initial - Previous reviewed SHA:
none - Review budget exhausted:
no - Maintainer decision required:
no - Next state:
gator:watch-pipeline
Summary
An API behind an access gateway may need two tokens on the same request: a gateway access token in
X-Gateway-Tokenand the API's own bearer token inAuthorization. OpenShell previously picked just one matching dynamic grant. This change lets the Supervisor get a separate token for each header and send the request only when every token is ready.Related Issue
Fixes #3320.
Changes
Testing
mise run pre-commitpassesChecklist