lahirujayathilake opened a new pull request, #497: URL: https://github.com/apache/airavata-custos/pull/497
## Summary Replaces the `X-Custos-User-Id` header trust pattern with verified OIDC bearer JWTs. - JWT verification middleware (signature, issuer, audience, expiry) with JWKS discovery via the issuer's `.well-known` document. - CORS middleware with a configurable origin allowlist. - A small `pkg/identity` package that carries the verified caller across the request lifecycle; handlers read identity from context instead of a request header. - `core.auth` and `core.cors` config blocks in `custos.yaml`; `OIDC_ISSUER_URL` and `OIDC_AUDIENCE` are required at boot. - Swagger annotations and the generated OpenAPI spec switched to `BearerAuth`. - All references to the legacy `X-Custos-User-Id` header are removed. Note - This `auth-endpoints` branch changes depends on the changes shipped with `nexus-portal`. Therefore the PR points to that branch to clearly show the changes. I'll update the target branch to `master` once the `nexus-portal` changes are merged into the `master` branch. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
