Commit 6e31491
feat(auth): make the runtime-token header configurable
Let the runtime-token JWT verifier read its token from a configurable
request header (env AGENT_CONTROL_RUNTIME_TOKEN_HEADER), defaulting to
Authorization so existing deployments are unaffected.
Why: when Agent Control runs behind an API gateway that reserves the
Authorization header for its own downstream identity JWT, the gateway
overwrites the runtime token on the hot evaluation path and the verifier
fails. Pointing the verifier at a dedicated header (e.g.
X-Agent-Control-Runtime-Token) lets the two tokens coexist.
- LocalJwtVerifyProvider gains a header_name param. On Authorization the
Bearer scheme prefix stays required (back-compat); on a dedicated header
the raw token is accepted (Bearer optional). The token is still
signature-verified, scope-checked, and target-bound after extraction, so
the header choice cannot bypass verification.
- config.py resolves the header via _resolve_runtime_token_header();
a whitespace-only env value falls back to the default.
- Tests: custom-header raw/Bearer acceptance, case-insensitive lookup,
no fallback to Authorization, whitespace/blank handling, and app-level
E2E through /api/v1/evaluation (gateway JWT on Authorization coexists
with the runtime token on a dedicated header).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>1 parent 8154980 commit 6e31491
4 files changed
Lines changed: 413 additions & 17 deletions
File tree
- server
- src/agent_control_server/auth_framework
- providers
- tests
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
24 | 28 | | |
25 | 29 | | |
26 | 30 | | |
| |||
39 | 43 | | |
40 | 44 | | |
41 | 45 | | |
| 46 | + | |
42 | 47 | | |
43 | 48 | | |
44 | 49 | | |
| |||
60 | 65 | | |
61 | 66 | | |
62 | 67 | | |
| 68 | + | |
63 | 69 | | |
64 | 70 | | |
65 | 71 | | |
| |||
378 | 384 | | |
379 | 385 | | |
380 | 386 | | |
381 | | - | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
382 | 391 | | |
383 | 392 | | |
384 | 393 | | |
385 | 394 | | |
386 | 395 | | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
387 | 411 | | |
388 | 412 | | |
389 | 413 | | |
| |||
Lines changed: 45 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
4 | | - | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
9 | 15 | | |
10 | 16 | | |
11 | 17 | | |
| |||
19 | 25 | | |
20 | 26 | | |
21 | 27 | | |
| 28 | + | |
| 29 | + | |
22 | 30 | | |
23 | 31 | | |
24 | 32 | | |
25 | 33 | | |
26 | | - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
27 | 40 | | |
28 | 41 | | |
| 42 | + | |
| 43 | + | |
29 | 44 | | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
30 | 50 | | |
31 | 51 | | |
32 | 52 | | |
| |||
79 | 99 | | |
80 | 100 | | |
81 | 101 | | |
82 | | - | |
| 102 | + | |
83 | 103 | | |
84 | 104 | | |
85 | 105 | | |
86 | | - | |
| 106 | + | |
87 | 107 | | |
88 | 108 | | |
89 | | - | |
90 | | - | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
91 | 113 | | |
92 | 114 | | |
93 | | - | |
94 | | - | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
95 | 126 | | |
96 | | - | |
| 127 | + | |
0 commit comments