lahirujayathilake opened a new pull request, #497:
URL: https://github.com/apache/airavata-custos/pull/497

   ## Summary
   
   Replaces the `X-Custos-User-Id` header trust pattern with verified OIDC 
bearer JWTs.
   
   - JWT verification middleware (signature, issuer, audience, expiry) with 
JWKS discovery via the issuer's `.well-known` document.
   - CORS middleware with a configurable origin allowlist.
   - A small `pkg/identity` package that carries the verified caller across the 
request lifecycle; handlers read identity from context instead of a request 
header.
   - `core.auth` and `core.cors` config blocks in `custos.yaml`; 
`OIDC_ISSUER_URL` and `OIDC_AUDIENCE` are required at boot.
   - Swagger annotations and the generated OpenAPI spec switched to 
`BearerAuth`.
   - All references to the legacy `X-Custos-User-Id` header are removed.
   
   
   Note - This `auth-endpoints` branch changes depends on the changes shipped 
with `nexus-portal`.  Therefore the PR points to that branch to clearly show 
the changes. I'll update the target branch to `master` once the `nexus-portal` 
changes are merged into the `master` branch.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to