m4
|
dbb6b7abde
|
feat(model-registry): add delegation-JWT auth and config/snapshot HTTP API
- BFF service token (constant-time, plaintext or SHA-256 hash) plus
X-Evo-Actor delegation JWT verification (ES256/RS256, iss/aud, <=60s
lifetime, required claims, thread binding) with atomic jti anti-replay
- Config API: GET/PUT /api/model-registry, credential rotation endpoint,
GET /api/models selector; PUT runs the section 9.2 save-time checks
inside the registry write transaction after credential writes
- Snapshot API: create/bind/delete routes delegating to SnapshotService
with thread/deployment binding checks and 9.5 unified error payloads
- Platform security config loader (config.yaml fields), OpenAPI export
(scripts/export_model_registry_schema.py -> model_registry/openapi.json)
- Mount new routes in langgraph_dev/http.py; retire the legacy
GET /api/models and POST /api/runtime-snapshots handlers
- Declare PyJWT>=2.8 (previously transitive); extend the 9.5 error code
table with the HTTP-layer codes (400/401/403/422/500)
|
2026-07-21 09:28:55 +08:00 |
|