Commit 1a5ed53
feat(gateway): accept API keys in inbound auth middleware
Phase 1. The auth chokepoint now resolves an identity from a valid JWT OR a
valid API key (host-issued, validated via the inbound-client repo): when there
is no valid JWT, a Bearer that matches a live key resolves to that key's
client_id. Falls through to 401 (auth on) / anonymous (auth off) exactly as
before. Lets headless/remote clients authenticate without the host-only OAuth
consent deep link.
Signed-off-by: Mohammod Al Amin Ashik <maa.ashik00@gmail.com>1 parent 2ebd004 commit 1a5ed53
1 file changed
Lines changed: 32 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
95 | 95 | | |
96 | 96 | | |
97 | 97 | | |
98 | | - | |
99 | | - | |
100 | | - | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
101 | 127 | | |
102 | 128 | | |
103 | | - | |
| 129 | + | |
104 | 130 | | |
105 | 131 | | |
106 | | - | |
| 132 | + | |
107 | 133 | | |
108 | 134 | | |
109 | 135 | | |
110 | | - | |
| 136 | + | |
111 | 137 | | |
112 | 138 | | |
113 | 139 | | |
| |||
0 commit comments