feat(providers): publish web-session credential contract - #11340
Merged
diegosouzapw merged 6 commits intoAug 25, 2026
Merged
diegosouzapw merged 6 commits into
diegosouzapw merged 6 commits into
Conversation
Owner
|
Clean, narrowly-scoped addition — we verified on the current release/v3.8.51 tip that the route sits behind requireManagementAuth before serialization, publishes only non-secret metadata (cookie/localStorage key names, never values), and that all 4 tests pass. Two suggestions, neither blocking: (1) the auth regression test greps the route source for the auth call — a behavioral test asserting GET without a management token returns 401/403 would survive refactors; (2) consider adding the endpoint to docs/openapi.yaml / API_REFERENCE.md so external broker integrators have a stable reference. Good separation from the larger Auth Keeper work. |
diegosouzapw
merged commit Aug 25, 2026
613fc71
into
diegosouzapw:release/v3.8.51
14 of 16 checks passed
arminanton
added a commit
to arminanton/OmniRoute
that referenced
this pull request
Aug 26, 2026
The uc persona is registered as a web-cookie provider, so the web-session credential contract (diegosouzapw#11340) requires it to declare its credential requirement in WEB_SESSION_CREDENTIAL_REQUIREMENTS; without it the create-connection UI can't describe what to paste and the coverage test (web-session-credentials) fails 'uc should declare its required web-session credential'. uc auth is the durable Clerk __client cookie plus session id + user id, all kept in providerSpecificData (kind: cookie, apiKey stays null). The storageKeys mirror the aliases resolveUcCredential() accepts so a seeded/imported connection is recognized as having a usable credential.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…w#11340) Merged into release/v3.8.51 via batch validation: node:test web-session-contract suite green on the combined tree, static gates green (file-size/complexity/cognitive/changelog/typecheck). Clean credential-contract surface — thanks @Zartharas!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Publish a management-authenticated, versioned web-session credential contract at
/api/providers/web-session-contract.The contract is derived from OmniRoute's canonical browser-session metadata:
listExtractionConfigs()getWebSessionCredentialRequirement()Only non-secret metadata is returned. Credential values, placeholders, instructions, polling configuration, and operator-only guidance are excluded.
Why
External credential brokers otherwise need to duplicate OmniRoute's browser-session credential schema and can drift as provider requirements change.
This is the narrow upstream-suitable contract-publication portion remaining after aggregate Auth Keeper integration work was separated into independent upstream fixes.
Scope
src/lib/providers/webSessionContract.tssrc/app/api/providers/web-session-contract/route.tstests/unit/web-session-contract.test.tsNo executor, routing, inference, scheduler, recovery, database, provider-asset, dashboard, CLI, or credential-value behavior changes.
Validation
Against active
release/v3.8.51base3192eb88d5550de4c3fd9985564f6b5641e9d681:Existing base-red full-repository lint
The active release base currently reports the known 22-error lint set across:
plus the existing stale-directive warning in EditConnectionModal.tsx.
All seven source blobs and the lint configuration are identical between the active release base and this PR head. This patch changes none of those files.
The exact 22-error set is the same release baseline tracked and fixed independently by merged upstream PR #11317.
Existing base-red provider asset gate
npm run check:provider-assetsreports:This is also inherited from the release base:
freebuff.pngblob;Broad PR CI remains authoritative for the repository-wide matrix.