Repository navigation
Update the playground to Barbacane 0.11.0 - #4
Merged
Merged
Conversation
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (13)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
0.11.0 forwards only the request headers an operation admits, and refuses an operation that runs an authentication middleware without naming the security scheme carrying the credential. The specs attached `oidc-auth` through `x-barbacane-middlewares` and declared no scheme, so they no longer compile: E1057: 'oidc-auth' authenticates the caller, so the operation must declare the security scheme carrying the credential Ten operations, seven in the train travel API and three in the S3 proxy, now name an `openIdConnect` scheme pointing at the mock issuer's discovery document. The requirement sits on each operation rather than at the document root, so the public asset route, the event channels and the WAF demos stay anonymous and admit no credential. No header needed declaring by hand. What the chain reads comes from the plugins' own configuration: `x-api-key` from the rate-limit partition, `x-request-id` and `x-event-id` from the correlation and event plugins, and `authorization` from the scheme above. `idempotency-key` and `accept-language` were already declared parameters. Verified against a running 0.11.0 stack, not only by compiling: 23 smoke checks pass. Compiling alone was not enough, because a malformed requirement can empty the middleware list, and E1057 then has no authentication plugin to check and passes for the wrong reason.
ndreno
force-pushed
the
feat/update-to-0.11.0
branch
from
September 17, 2026 22:39
1e577f9 to
506480f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings the playground to 0.11.0, released today. The branch also carries the unmerged 0.10.0 update and the CI work, since neither reached
main.What 0.11.0 required
Two breaking changes touch the specs.
A security scheme where a middleware authenticates. Ten operations attached
oidc-auththroughx-barbacane-middlewaresand declared no scheme, so they stopped compiling:Seven operations in the train travel API and three in the S3 proxy now name an
openIdConnectscheme pointing at the mock issuer's discovery document. The requirement sits on each operation rather than at the document root, so the public asset route, the six event channels and the three WAF demos stay anonymous and admit no credential.Headers the document does not describe no longer reach the upstream. Nothing needed declaring by hand. Everything the chain reads comes from the plugins' own configuration:
x-api-keyfrom the rate-limit partition key,x-request-idandx-event-idfrom the correlation and event plugins,authorizationfrom the scheme above.idempotency-keyandaccept-languagewere already declared parameters.Verified against a running stack
A clean compile was not sufficient evidence here, and it is worth recording why.
A first attempt placed the requirement directly after the
x-barbacane-middlewares:key, which emptied the middleware list and swallowed theoidc-authentry into the security block. Authentication was off on all ten operations, and the compile still passed — with no authentication plugin left in the chain, E1057 has nothing to check. The only tell was the bundled plugin count dropping from eleven to nine.The smoke test caught it, on
GET /bookings without a tokenreturning 200 instead of 401.After the fix, against the 0.11.0 stack: 23 checks pass, 0 fail, covering validation, the OIDC token flow, protected bookings, NATS dispatch, the S3 round trip, MCP initialize, CORS preflight, the WAF request and response phases, the admin API and the Prometheus scrape.
Version
BARBACANE_VERSIONmoves to 0.11.0 in.env.example, the compose defaults and the README. Both 0.11.0 images were confirmed pullable from ghcr.io before this was prepared.Summary by CodeRabbit
New Features
Bug Fixes
Tests