Skip to content

fix(openapi): support isolated per-request upstream credentials - #638

Merged
amitdeshmukh merged 1 commit into
masterfrom
fix/openapi-request-credentials
Sep 11, 2026
Merged

amitdeshmukh merged 1 commit into
masterfrom
fix/openapi-request-credentials

Conversation

@amitdeshmukh

Copy link
Copy Markdown
Collaborator

OpenAPI sources could only use shared credentials through GraphQL and HTTP MCP: token_from_request existed, but incoming credentials never reached the operation caller. This change carries explicitly configured credential headers in request context, so two users can query or mutate the same source with separate upstream accounts.

  • Covers top-level reads, remote joins, and mutations through GraphQL and both HTTP MCP handlers. Adds openapi.WithRequestHeaders for Go hosts.
  • Rejects missing, blank, repeated, or malformed credential headers and configurations combining request tokens with static credentials. Detached contexts cannot use credentials after the original request ends.
  • Bypasses personal API fragment caching and background refresh. HTTP responses on deployments with request-token sources use private, no-store, including MCP streaming responses.
  • Rejects subscriptions using personal credentials and makes concurrent subscribers consistently observe initialization failures.

OAuth consent, account ownership, token storage, and refresh remain the host application's responsibility. Subscription support and narrowing HTTP cache suppression to selected sources are outside this change.

Validation:

  • go test ./core/... ./serv/...
  • go test -race ./core ./core/openapi ./serv -run 'Test(OpenAPIRequestCredentialsHTTP|RequestCredential|BearerAuth|ApiKeyAuth|Subscription)' -count=1
  • Regression coverage exercises concurrent users, reconnecting one app identity to another upstream account, missing credentials, enabled fragment caching, GET cache headers, and concurrent subscription rejection against an HTTP test upstream.

@amitdeshmukh
amitdeshmukh merged commit 139ec4f into master Sep 11, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant