Skip to content

control-plane-api: accept a prefix scope header - #3407

Draft
GregorShear wants to merge 1 commit into
masterfrom
greg/scoped-prefix-header
Draft

GregorShear wants to merge 1 commit into
masterfrom
greg/scoped-prefix-header

Conversation

@GregorShear

@GregorShear GregorShear commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

An authenticated client can send X-Estuary-Scope-Prefix: acmeCo/ to narrow a request using the existing prefix_scope authorization policy. With an unscoped bearer, changing the header switches the selected tenant without obtaining another token; delegated prefixes remain available according to the existing grant graph.

Envelope applies the header to a request-local copy of verified claims. Existing handlers and credential-creation guards consume those effective claims. The header is also allowed by CORS. Omitting it preserves existing behavior.

A token that already carries prefix_scope accepts only a matching header, using the token's existing trailing-slash normalization. A different header returns HTTP 400, including a textual child prefix: graph scopes cannot safely be composed by string containment. Empty, malformed, non-ASCII, and repeated headers return HTTP 400; a valid header without authentication returns HTTP 401. Capability masks remain intact.

The change is limited to request extraction, the CORS allowlist, documentation, and tests. It uses the authorization machinery merged in #3543 without changing grant traversal, legacy capabilities, database schemas, or dashboard code.

Validation:

  • cargo check -p control-plane-api with SQLX_OFFLINE=true.
  • Five focused nextest tests: parsing, authentication, existing token restrictions, grant-graph authorization, and HTTP behavior (GraphQL tenant switching, credential-creation refusal, and CORS preflight).
  • cargo fmt --all --check and git diff --check.

The test build used temporary SQLx metadata for ten existing test-only queries missing from the checked-in cache. No metadata or database changes are included. The full API test suite was not run.

@GregorShear GregorShear closed this Oct 5, 2026
@GregorShear GregorShear reopened this Oct 5, 2026
@GregorShear
GregorShear force-pushed the greg/scoped-prefix-header branch from 8344dd9 to c5b70ee Compare October 5, 2026 16:54
@GregorShear GregorShear changed the title authz: scope a request's authority to one branch of the grant graph control-plane-api: accept a prefix scope header Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant