feat: add fail-closed Hub access profile foundation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
df39fd5f43
commit
3e386147fd
35 changed files with 2009 additions and 195 deletions
|
|
@ -99,7 +99,10 @@ def create_inbox_projection_router() -> APIRouter:
|
|||
settings = request.app.state.settings
|
||||
token = settings.api_token
|
||||
supplied = (authorization or "").removeprefix("Bearer ")
|
||||
if not token or not (authorization or "").startswith("Bearer ") or not hmac.compare_digest(supplied, token):
|
||||
if settings.enforce_access:
|
||||
if getattr(request.state, "hub_access", None) is None:
|
||||
raise HTTPException(503, "access boundary unavailable")
|
||||
elif not token or not (authorization or "").startswith("Bearer ") or not hmac.compare_digest(supplied, token):
|
||||
raise HTTPException(401, "inbox pilot requires operator bearer authentication",
|
||||
headers={"WWW-Authenticate": "Bearer"})
|
||||
if to_agent != settings.statehub_inbox_agent:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue