• v0.2.0 b1b11330a6

    Add per-role HTTP method scoping to minted tokens (#2)
    ci/woodpecker/tag/release Pipeline was successful

    unkin-agent released this 2026-08-30 14:45:04 +10:00 | 0 commits to main since this release

    Why

    Every token this engine mints is as powerful as the apps it can reach, so a read-only integration can still write to the *arr. arrproxy now accepts a method scope at mint time, and the engine has no way to ask for one.

    How

    • Add an optional methods role field, uppercase-normalized and de-duplicated.
    • Reject a method outside GET/HEAD/POST/PUT/PATCH/DELETE/OPTIONS at role write.
    • Forward the role's scope on the arrproxy mint request and echo it in the creds response.
    • Omit the field when a role has no scope, so unscoped roles behave exactly as before.
    • Cover normalization, rejection, pass-through and the unscoped case.

    Requires arrproxy >= v0.5.0 deployed.

    Reviewed-on: #2
    Co-authored-by: unkin-agent unkin-agent@unkin.net
    Co-committed-by: unkin-agent unkin-agent@unkin.net

    Downloads