Full-surface integration suite (tests/full_surface.rs, mcp feature): - one HttpAdapter over real TCP (ProtocolHandler::handle path) serving gateway endpoints, /openapi.json, /mcp, and the WS channels session - gateway: search/schema/call/subscribe/batch/publish presence, envelope shapes, error fidelity end-to-end - from_openapi import -> Internal-by-default invisible from the wire -> External facade composes it via env.invoke -> upstream HTTP API called end-to-end (ADR-015 composition model exercised) - to_openapi 6-path doc validated against openapiv3 over the wire - to_mcp: MCP client connects to /mcp on the served adapter, lists the 4 gateway tools, search returns ACL-filtered ops (Sub excluded) Production fix: the WS upgrade route was reserved but never wired into HttpAdapter's router (the ws-upgrade-session tests built their own router). Now wired with ws_bearer_auth (401 without a resolvable token) around ws_upgrade_handler. Docs sync: all 28 'Port notes' sections/blockquotes stripped from ported ADRs/specs; OQ-01/OQ-02 statuses corrected to resolved in overview.md, websocket.md, and the README table (open-questions.md was already current). Publish prep: cargo publish --dry-run --allow-dirty succeeds; cargo doc --no-deps warning-free (ADR link targets fixed); feature combinations (default / test-support / mcp / wss / all) compile warning-free under clippy -D warnings. Verified: cargo test (182 lib default), --all-features (227 lib + 29 integration), clippy -D warnings x3 feature sets, fmt, doc, publish --dry-run.
5.9 KiB
ADR-004: Auth as Shared Core (IdentityProvider)
Ported from alknet ADR-004 (Auth as Shared Core (IdentityProvider)); re-targeted to alkhttp.
Status
Accepted
Context
The previous architecture had authentication spread across multiple layers: CredentialProvider with four phases (A–D), AuthProtocol as an irpc service, server_auth and client_auth as separate modules, and IdentityProvider as a trait in the core. Different interface types presented credentials differently — SSH used key fingerprints, HTTP used Bearer tokens, DNS used query labels — but the resolution was ad-hoc and tied to the three-layer model.
The ALPN dispatch model simplifies this: every handler receives the same AuthContext, but the credential extraction (how a handler learns who the peer is) differs per ALPN. The resolution (turning a credential into an Identity) should be shared across all handlers.
Decision
Note
: The original text of this decision described the handler "enriching or replacing" the
AuthContext. This was superseded by ADR-011, which madeAuthContextimmutable inhandle()(passed as&AuthContext). Handlers resolve identity into a local variable and store it onConnectionviaset_identity(). The text below has been updated to reflect the ADR-011 model.
Authentication and identity resolution live in the shared core (now vendored in alkcall) as shared infrastructure. Each handler presents credentials differently, but all resolve through the same IdentityProvider:
pub trait IdentityProvider: Send + Sync + 'static {
fn resolve_from_fingerprint(&self, fingerprint: &str) -> Option<Identity>;
fn resolve_from_token(&self, token: &AuthToken) -> Option<Identity>;
}
Credential presentation per handler:
| Handler | Credential presentation | Resolves via |
|---|---|---|
| SshAdapter | SSH public key handshake | resolve_from_fingerprint() |
| CallAdapter | AuthToken in first frame | resolve_from_token() |
| HttpAdapter | Authorization: Bearer header |
resolve_from_token() |
| DnsAdapter | AuthToken in query labels | resolve_from_token() |
| WebTransportAdapter | AuthToken in CONNECT headers | resolve_from_token() |
| GitAdapter | Signed push certificate | resolve_from_fingerprint() |
Auth resolution is hybrid — the endpoint resolves what it can, and handlers resolve what they must:
-
Endpoint-level resolution (before
handle()is called): If the TLS handshake provides a client certificate, the endpoint resolves the fingerprint to anIdentityand passes it inAuthContext. This is the case for SSH (where the key exchange happens at the protocol level, but the TLS layer may also provide information). -
Handler-level resolution (inside
handle()): For protocols that carry credentials in application frames (AuthToken in the first call frame, Bearer header in HTTP), the handler extracts the credential from the stream and callsIdentityProviderto resolve it. The handler then resolves theIdentityinto a local variable and stores it on theConnectionviaset_identity()for observability — it does not mutate theAuthContext(which is passed as&AuthContext, an immutable reference — see ADR-011). The per-request identity (for ACL) is resolved separately by theCallAdapteratcall.requestedtime.
The AuthContext passed to handle() may be partial — containing only transport-level information if no TLS client certificate was provided. Handlers must not assume AuthContext contains a fully resolved Identity. Each handler knows its own credential extraction protocol and is responsible for completing authentication.
The CredentialProvider concept from the previous architecture is simplified: there is no phase progression (A–D). The IdentityProvider has two resolution paths — fingerprint and token — and a ConfigIdentityProvider implementation that draws from static and dynamic config.
alkvault stays standalone. It does not depend on the core crate or IdentityProvider. The vault provides derived keys on request; identity resolution is a separate concern.
Consequences
Positive:
- Unified identity model — every handler resolves identities the same way through
IdentityProvider - Handlers own their credential extraction — SSH reads key fingerprints, call reads AuthTokens, HTTP reads Bearer headers
- Endpoint provides what it can for free (TLS-level auth), handlers complete what they need
- Adding a new credential type is adding a method to
IdentityProvider, not a new phase - The vault stays standalone — no coupling between key derivation and identity resolution
AuthContextis a value type — easy to construct in tests, can be partial for handler-level testing
Negative:
IdentityProvideris in the core crate — any change to it recompiles all handlers (mitigated: the trait should be stable; implementation changes don't force recompiles)- Two resolution paths (fingerprint, token) may not cover all future auth schemes (mitigated: the trait can be extended, or a handler can do custom resolution after the initial AuthContext)
- Handlers must handle partial AuthContext — the endpoint may not have resolved an Identity, so handlers must be prepared to do credential extraction themselves
- WebTransport and browser-based auth needs careful design — AuthToken in CONNECT headers requires the token to be available before the stream is established
References
- Pivot proposal (alknet mono-repo):
docs/research/pivot/alpn-service-architecture.md - ADR-002: ProtocolHandler trait
- ADR-003: Crate decomposition
- ADR-005: irpc as call protocol foundation
- The previous architecture had equivalent decisions in ADR-023 (unified auth) and ADR-029 (identity as core type), which are archived in the reference implementation at
/workspace/@alkdev/alknet-main/.