Skip to content

Flow finalized DownstreamApi request before authorization header creation#3902

Merged
4gust merged 3 commits into
masterfrom
bgavril/mise-shr-request-ordering
Jul 1, 2026
Merged

Flow finalized DownstreamApi request before authorization header creation#3902
4gust merged 3 commits into
masterfrom
bgavril/mise-shr-request-ordering

Conversation

@bgavrilMS

Copy link
Copy Markdown
Member

Summary

  • finalize DownstreamApi request headers, query parameters, content, and customizations before creating the authorization header
  • keep Authorization added after signing so request-binding providers do not include it in their signed material
  • add coverage that the authorization provider sees the final request state

Context

This supports MISE outbound SHR q/h/b signing by ensuring request-binding authorization providers receive the same HTTP request state that will be sent on the wire.

@bgavrilMS
bgavrilMS requested a review from a team as a code owner June 30, 2026 10:25
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@bgavrilMS
bgavrilMS force-pushed the bgavril/mise-shr-request-ordering branch from c4dca5e to 45ff3be Compare July 1, 2026 11:07
Verifies that reserved header names supplied via ExtraHeaderParameters remain
skipped both on the request flowed to the authorization header provider and
on the final outgoing request, ensuring the request-ordering change did not
alter the reserved/duplicate-skip semantics.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@4gust
4gust merged commit b192389 into master Jul 1, 2026
4 checks passed
@4gust
4gust deleted the bgavril/mise-shr-request-ordering branch July 1, 2026 13:19
This was referenced Jul 3, 2026
This was referenced Jul 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants