Conversation
Carry gateway-derived endpoint owners through policy and credential delivery. Select grants only from owners that admit the current request, refresh provider snapshots per request, and reject superseded installations before forwarding. Cover persistent routes, overlapping owners, denial, refresh, cache expiry and recovery with focused tests and a Podman regression. Signed-off-by: Shiju <shiju@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Requests to different provider paths on one host now acquire the grant belonging to an endpoint that admitted that request. The relay checks each request on a persistent connection against current provider state, and rejects a grant if policy or provider installation changes before forwarding. This adds the missing multi-route hook and applies the same ownership checks to existing single-route REST injection.
Related Issue
Closes #3657
The implementation covers #3657's multi-route injection, isolation, persistent connections, failure recovery and refresh/expiry requirements. Native single-route MCP/JSON-RPC remains tracked separately in #3658, as #3657 permits. Native single-route GraphQL also still lacks its injection hook; this PR does not claim to add it. The broader issuer-expiry/TTL correction remains separate.
Changes
Host.Testing
Checklist