This is an automated email from the ASF dual-hosted git repository.
lahirujayathilake pushed a change to branch auth-endpoints
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
at 689e43be7 Drop stale Missing caller header from privilege swag
This branch includes the following new commits:
new e1d03667f Add auth config block for issuer, audience, JWKS URL
new b08489cc6 Add pkg/identity for caller context propagation
new c3cf8e2f1 Add JWT verification middleware with JWKS discovery
new ed26a034e Add CORS middleware reading origins from config
new 951e060dc Tighten auth error responses to opaque 401
new 528905c9a Wire auth and CORS middleware into the server entrypoint
new 8535531c9 Read caller identity from context, not the user-id header
new 3598ef533 Inject caller via context in integration test harness
new 1360dc0eb Switch swagger annotations to BearerAuth scheme
new 33220e7c8 Sweep remaining swagger annotations to BearerAuth scheme
new 7a2623d01 Parameterize portal origin in the CORS allowlist
new bf68d4bb1 Drop custos.yaml.example, fold the one useful hint inline
new 55e5dad8e Set Vary: Origin on every cross-origin response and cover
with tests
new ca66ea90e Refresh JWKS on unknown signing key and tighten URL lock
invariant
new 689e43be7 Drop stale Missing caller header from privilege swag
The 15 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.