Repository navigation
feat(platform): accept a host-verified identity in bearer auth - #516
Open
angel-romero-flo wants to merge 2 commits into
Open
angel-romero-flo wants to merge 2 commits into
angel-romero-flo wants to merge 2 commits into
Conversation
A process embedding the platform router can verify a caller from a credential the platform cannot interpret and insert a HostVerifiedIdentity request extension before the router. bearer_auth_check removes the extension, drops the Authorization header, and authenticates the request as that principal in the requested tenant; that tenant's Cedar policy still authorizes it. Request extensions cannot be set over HTTP, so no header produces this identity.
…entities A request authenticated by a HostVerifiedIdentity carries its X-Session-Id and X-Intent values on the authenticated context as telemetry, as the credential path does for an unverified session; neither becomes a Cedar input. Tests cover that, and that the requested tenant's Cedar policy denies a host-verified identity until a policy permits it.
angel-romero-flo
force-pushed
the
host-verified-identity
branch
from
October 5, 2026 15:46
6218bc9 to
2157f71
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A host that embeds the platform router can authenticate callers from credentials the platform cannot interpret (for example, Datadog Internal Service Authentication JWTs validated by the host against rotating keys). The only way to get such a caller into
bearer_auth_checktoday is to mint and register a second credential the platform can resolve (a trusted issuer plus a host-side signing key, or anAgentCredentialper caller). A protected request without a resolvable credential gets401, even when an outer layer already verified the caller.Change
temper_platform::host_identity::HostVerifiedIdentity(pub SecurityContext): a principal the host verified in its own middleware, in front of the platform router.bearer_auth_checkchecks for it right after parsing the tenant, before the internal-invocation branch. When present, it removes the extension and theAuthorizationheader, and attachesAuthenticatedRequestContext::new(<requested tenant>, <context>). Session and intent headers become telemetry on that context, as on the credential path for a session nobody verified; neither becomes a Cedar input.This branch is based directly on
nerdsane/temper:main(1be4b7be003f35bdacfbc24f7f4eb7e77bdade48); the fork only supplies the source branch. The consumer is Datadog's temper-cloud control plane. It validates ISA tokens withddauthnand attaches the caller asCustomer::"<email>", which removes its current token-minting exchange.Verification
bearer_auth/tests.rs, all throughstrip_inbound_identity_headersandbearer_auth_check:Customer::"ada@example.com", and the request also carries anAuthorization: Bearerthat no credential resolves withX-Tenant-Id: tenant-a:200, the handler seestenant-a:Customer:ada@example.comand noAuthorizationheader;401;X-Session-IdandX-Intent: both reach the context as telemetry, and the CedarsessionIdstays unset;build_platform_router, a host identity reading/tdata/AgentTypesin a tenant with no Cedar policy:403; after loading a policy that permitsCustomer:200.The first and third tests failed with their code disabled and pass with it. All 25 tests in the module pass, including the existing ones (headers cannot forge identity, tenant-bound credentials, public routes).
cargo fmt --check,scripts/readability-ratchet.sh check .ci/readability-baseline.env(blocking metrics OK), andcargo clippy --workspace --all-targets -- -D warnings: clean.cargo test --workspace --no-fail-fast, with a local PostgreSQL in place of testcontainers (TEMPER_ACTOR_TEST_DATABASE_URL): 3525 passed, 0 failed, 12 ignored. In an earlier run of this suite,temper-wasmhttp_stream_outbound::outbound_streaming_1mib_roundtripfailed intermittently (933888of1048576bytes received). It also fails 1 of 3 runs onmain, andtemper-wasmdoes not depend ontemper-platform.The PR appears safe to merge; no outstanding findings or new actionable issues remain.
Summary
The PR lets an embedding host supply a verified identity to bearer authentication while retaining requested-tenant policy authorization.
Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR H[Host verifies caller] --> E[HostVerifiedIdentity extension] E --> B[Bearer authentication binds requested tenant] B --> C[Authenticated request context] C --> P[Tenant Cedar policy] P -->|Permit| R[Protected route] P -->|Deny| F[403]Reviews (3) · Last reviewed commit: "fix(platform): keep session and intent t..."