This is an automated email from the ASF dual-hosted git repository.
lahirujayathilake pushed a change to branch auth-endpoints
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
at 39eb0f80c Drop stale Missing caller header from privilege swag
This branch includes the following new commits:
new a84d55488 Add auth config block for issuer, audience, JWKS URL
new a1f34c559 Add pkg/identity for caller context propagation
new 3802fd5db Add JWT verification middleware with JWKS discovery
new f090e1061 Add CORS middleware reading origins from config
new 4644419c2 Tighten auth error responses to opaque 401
new fb26181c6 Wire auth and CORS middleware into the server entrypoint
new 49beee150 Read caller identity from context, not the user-id header
new a76bb3434 Inject caller via context in integration test harness
new 326f47285 Switch swagger annotations to BearerAuth scheme
new 61183f73e Sweep remaining swagger annotations to BearerAuth scheme
new 533b1b008 Parameterize portal origin in the CORS allowlist
new eb909c741 Drop custos.yaml.example, fold the one useful hint inline
new a6d31b4d8 Set Vary: Origin on every cross-origin response and cover
with tests
new 6b8e7d66b Refresh JWKS on unknown signing key and tighten URL lock
invariant
new 39eb0f80c Drop stale Missing caller header from privilege swag
The 15 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.