docs: 📝 retrofit openspec for stateless-http-auth (#137) #139

Merged
goern merged 0 commits from refs/pull/139/head into main 2026-05-25 08:08:36 +00:00
goern commented 2026-05-24 06:36:47 +00:00 (Migrated from codeberg.org)

Summary

Retrofits an OpenSpec change capturing the per-request HTTP/SSE authentication design landed in PR #138 (issue #137).

Adds:

  • proposal.md — why (issue #137) + what changes
  • design.md — architectural decisions, including D3 (no silent fallback) and D4 (case-insensitive scheme)
  • tasks.md — checked boxes for shipped work in #138, unchecked boxes for the three open review blockers
  • specs/stateless-http-auth/spec.md — formal capability spec with scenarios

Why now

PR #138 ships the feature but openspec validate had no capability to point at, and the review on #138 produced three load-bearing rules (silent-fallback ban, case-insensitive scheme, real isolation test) that deserve to live in a spec rather than only a PR comment.

This PR is intentionally docs-only — no code touched. Merges after #138 lands its blocker fixes; then this change archives.

Test plan

  • openspec validate stateless-http-auth --strict passes
  • Follows the same structure as archive/2026-05-12-add-bounded-text-responses/
  • Cross-reference from README "Multi-tenant HTTP mode" section once PR #138 adds it
  • Archive under openspec/changes/archive/<date>-stateless-http-auth/ after #138 merges

Refs #137, #138.

## Summary Retrofits an OpenSpec change capturing the per-request HTTP/SSE authentication design landed in PR #138 (issue #137). Adds: - `proposal.md` — why (issue #137) + what changes - `design.md` — architectural decisions, including D3 (no silent fallback) and D4 (case-insensitive scheme) - `tasks.md` — checked boxes for shipped work in #138, unchecked boxes for the three open review blockers - `specs/stateless-http-auth/spec.md` — formal capability spec with scenarios ## Why now PR #138 ships the feature but `openspec validate` had no capability to point at, and the review on #138 produced three load-bearing rules (silent-fallback ban, case-insensitive scheme, real isolation test) that deserve to live in a spec rather than only a PR comment. This PR is intentionally docs-only — no code touched. Merges after #138 lands its blocker fixes; then this change archives. ## Test plan - [x] `openspec validate stateless-http-auth --strict` passes - [x] Follows the same structure as `archive/2026-05-12-add-bounded-text-responses/` - [ ] Cross-reference from README "Multi-tenant HTTP mode" section once PR #138 adds it - [ ] Archive under `openspec/changes/archive/<date>-stateless-http-auth/` after #138 merges Refs #137, #138.
goern commented 2026-05-24 06:48:26 +00:00 (Migrated from codeberg.org)

@fsryanorg — would love your eyes on this one, since it formalises the design that answers your ask in #137.

this PR doesn't ship code. it captures the per-request auth design (proposal + design + spec) so the rules behind PR #138 are written down somewhere other than my review comments. the topology diagram you drew in #137 is basically the load-bearing motivation in proposal.md.

what i'd value most:

  • does the spec actually describe the behaviour you need for your distributed-agent setup, or am i missing a case?
  • the three unchecked blockers in tasks.md (silent fallback, case-insensitive scheme, real isolation test) — does any of those feel like a non-blocker to you, or did i miss one that matters for your use case?

no rush. merges after #138 lands its fixes.

@fsryanorg — would love your eyes on this one, since it formalises the design that answers your ask in #137. this PR doesn't ship code. it captures the per-request auth design (proposal + design + spec) so the rules behind PR #138 are written down somewhere other than my review comments. the topology diagram you drew in #137 is basically the load-bearing motivation in `proposal.md`. what i'd value most: - does the spec actually describe the behaviour you need for your distributed-agent setup, or am i missing a case? - the three unchecked blockers in `tasks.md` (silent fallback, case-insensitive scheme, real isolation test) — does any of those feel like a non-blocker to you, or did i miss one that matters for your use case? no rush. merges after #138 lands its fixes.
goern commented 2026-05-24 07:16:03 +00:00 (Migrated from codeberg.org)

/test on-pull-request

(verifying op1st PaC webhook now subscribes to pull_request events — was push-only, fixed in webhook id 60326. tracked in bd forgejo-mcp-5x8.)

/test on-pull-request (verifying op1st PaC webhook now subscribes to pull_request events — was push-only, fixed in webhook id 60326. tracked in bd `forgejo-mcp-5x8`.)
op1st-gitops commented 2026-05-24 07:16:14 +00:00 (Migrated from codeberg.org)

op1st Pipelines as Code/on-pull-request-cnffg is running.

Starting Pipelinerun on-pull-request-cnffg in namespace op1st-pipelines

You can monitor the execution using the op1st Pipelines as Code PipelineRun viewer or through the command line by
using the tkn CLI with the following command:

tkn pr logs -n op1st-pipelines on-pull-request-cnffg -f

op1st Pipelines as Code/on-pull-request-cnffg is running. Starting Pipelinerun <b>[on-pull-request-cnffg](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/on-pull-request-cnffg)</b> in namespace <b>op1st-pipelines</b> You can monitor the execution using the [op1st Pipelines as Code](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/on-pull-request-cnffg) PipelineRun viewer or through the command line by using the [tkn](https://tekton.dev/docs/cli/#installation) CLI with the following command: <code>tkn pr logs -n op1st-pipelines on-pull-request-cnffg -f</code>
op1st-gitops commented 2026-05-24 07:17:50 +00:00 (Migrated from codeberg.org)

op1st Pipelines as Code/on-pull-request-cnffg has successfully validated your commit.


Task Statuses:

StatusDurationName
Succeeded 19 seconds

fetch-source

Succeeded 1 minute

build-and-test

op1st Pipelines as Code/on-pull-request-cnffg has <b>successfully</b> validated your commit. <ul> <li><b>Namespace</b>: <a href="https://detailurl.setting.custom-console-url-namespace.is.not.configured">op1st-pipelines</a></li> <li><b>PipelineRun:</b> <a href="https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/on-pull-request-cnffg">on-pull-request-cnffg</a></li> </ul> <hr> <h4>Task Statuses:</h4> <table> <tr><th>Status</th><th>Duration</th><th>Name</th></tr> <tr> <td>Succeeded</td> <td>19 seconds</td><td> [fetch-source](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/on-pull-request-cnffg/logs/fetch-source) </td></tr> <tr> <td>Succeeded</td> <td>1 minute</td><td> [build-and-test](https://console-openshift-console.apps.nostromo.erdgeschoss.b4mad.emea.operate-first.cloud/k8s/ns/op1st-pipelines/tekton.dev~v1~PipelineRun/on-pull-request-cnffg/logs/build-and-test) </td></tr> </table>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
agentic-forges/forgejo-mcp!139
No description provided.