Skip to content

Update the playground to Barbacane 0.11.0 - #4

Merged
ndreno merged 1 commit into
mainfrom
feat/update-to-0.11.0
Sep 17, 2026
Merged

ndreno merged 1 commit into
mainfrom
feat/update-to-0.11.0

Conversation

@ndreno

@ndreno ndreno commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Brings the playground to 0.11.0, released today. The branch also carries the unmerged 0.10.0 update and the CI work, since neither reached main.

What 0.11.0 required

Two breaking changes touch the specs.

A security scheme where a middleware authenticates. Ten operations attached oidc-auth through x-barbacane-middlewares and declared no scheme, so they stopped compiling:

E1057: 'oidc-auth' authenticates the caller, so the operation must declare
the security scheme carrying the credential

Seven operations in the train travel API and three in the S3 proxy now name an openIdConnect scheme pointing at the mock issuer's discovery document. The requirement sits on each operation rather than at the document root, so the public asset route, the six event channels and the three WAF demos stay anonymous and admit no credential.

Headers the document does not describe no longer reach the upstream. Nothing needed declaring by hand. Everything the chain reads comes from the plugins' own configuration: x-api-key from the rate-limit partition key, x-request-id and x-event-id from the correlation and event plugins, authorization from the scheme above. idempotency-key and accept-language were already declared parameters.

Verified against a running stack

A clean compile was not sufficient evidence here, and it is worth recording why.

A first attempt placed the requirement directly after the x-barbacane-middlewares: key, which emptied the middleware list and swallowed the oidc-auth entry into the security block. Authentication was off on all ten operations, and the compile still passed — with no authentication plugin left in the chain, E1057 has nothing to check. The only tell was the bundled plugin count dropping from eleven to nine.

The smoke test caught it, on GET /bookings without a token returning 200 instead of 401.

After the fix, against the 0.11.0 stack: 23 checks pass, 0 fail, covering validation, the OIDC token flow, protected bookings, NATS dispatch, the S3 round trip, MCP initialize, CORS preflight, the WAF request and response phases, the admin API and the Prometheus scrape.

Version

BARBACANE_VERSION moves to 0.11.0 in .env.example, the compose defaults and the README. Both 0.11.0 images were confirmed pullable from ghcr.io before this was prepared.

Summary by CodeRabbit

  • New Features

    • Added OpenID Connect protection for bookings, payments, and private storage operations.
    • Added outbound response inspection to block responses containing exposed AWS credentials.
    • Added WAF audit logging for inspected transactions.
    • Exposed health and metrics at the admin endpoint for monitoring.
    • Updated the playground to Barbacane 0.11.0.
  • Bug Fixes

    • Corrected Prometheus metrics scraping configuration.
  • Tests

    • Added automated smoke tests covering authentication, APIs, WAF protections, monitoring, and core playground services.
    • Added continuous integration checks for pull requests, main-branch updates, scheduled runs, and manual execution.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c2855bb2-7845-4683-9fce-ffa278406350

📥 Commits

Reviewing files that changed from the base of the PR and between 1a4bfb2 and 1e577f9.

📒 Files selected for processing (13)
  • .env.example
  • .github/workflows/ci.yml
  • README.md
  • configs/prometheus/prometheus.yml
  • docker-compose.yml
  • playground.http
  • scripts/smoke.sh
  • specs/s3-proxy.yaml
  • specs/train-travel-api.yaml
  • specs/waf-demo.yaml
  • specs/waf-rules/010-attacks.conf
  • specs/waf-rules/030-response.conf
  • specs/waf-rules/040-response-blocking.conf
 ______________________________________________________________________
< I see you chose the 'dynamic typing' difficulty setting. On purpose. >
 ----------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

0.11.0 forwards only the request headers an operation admits, and refuses
an operation that runs an authentication middleware without naming the
security scheme carrying the credential. The specs attached `oidc-auth`
through `x-barbacane-middlewares` and declared no scheme, so they no
longer compile:

  E1057: 'oidc-auth' authenticates the caller, so the operation must
  declare the security scheme carrying the credential

Ten operations, seven in the train travel API and three in the S3 proxy,
now name an `openIdConnect` scheme pointing at the mock issuer's
discovery document. The requirement sits on each operation rather than at
the document root, so the public asset route, the event channels and the
WAF demos stay anonymous and admit no credential.

No header needed declaring by hand. What the chain reads comes from the
plugins' own configuration: `x-api-key` from the rate-limit partition,
`x-request-id` and `x-event-id` from the correlation and event plugins,
and `authorization` from the scheme above. `idempotency-key` and
`accept-language` were already declared parameters.

Verified against a running 0.11.0 stack, not only by compiling: 23 smoke
checks pass. Compiling alone was not enough, because a malformed
requirement can empty the middleware list, and E1057 then has no
authentication plugin to check and passes for the wrong reason.
@ndreno
ndreno force-pushed the feat/update-to-0.11.0 branch from 1e577f9 to 506480f Compare September 17, 2026 22:39
@ndreno
ndreno merged commit b241c35 into main Sep 17, 2026
3 checks passed
@ndreno
ndreno deleted the feat/update-to-0.11.0 branch September 17, 2026 22:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant