Skip to content

feat(dgw): add a TASK token for background tasks - #2006

Draft
irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 3 commits into
feat/ai-cratefrom
feat/task-token
Draft

irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 3 commits into
feat/ai-cratefrom
feat/task-token

Conversation

@irvingoujAtDevolution

@irvingoujAtDevolution irvingouj@Devolutions (irvingoujAtDevolution) commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

New TASK token so DVLS can ask Gateway to run a background task on one target. Claims: jet_tk (task kind, only ai-log today) + the kind's target (jet_aid for ai-log), and the usual jet_gw_id / nbf / exp / jti. Always single use: consumed as soon as Gateway receives it.

The token never carries the AI key; that goes in the request body, same as provision-credentials. Also adds the gateway.tasks.read scope for polling, TaskClaims.ForAiLog(...) with a typed TaskKind in the .NET utils, and tokengen sign task.

Tested: token lib tests 11/11, dvls_compatibility 24/24, .NET utils tests 32/32.

Stacked on #2005.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Remove the `jet_task_reuse` claim from the Gateway, the .NET `TaskClaims`,
and tokengen. The token cache now rejects any second use of a TASK token.
Reuse can come back later as an optional claim without breaking anyone.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Add a `TaskKind` struct with a JSON converter, in the same style as
`RecordingOperation`, with `AiLog` serialized as "ai-log".

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant