Conversation
Request a token from /connect/token with a form body, cache it until shortly before expiry, share one in-flight refresh between callers and keep secrets out of repr and errors. Certificates and host names are always verified; a self-signed development certificate is trusted only for loopback hosts.
Add the bearer-token channel interceptor, wire-value conversion, and a client that ensures an event store and namespace, registers a schema and appends to the event log. Declare grpcio, which the client now imports directly, and register the integration marker.
…ote hosts The transport did a single read, so a response split across TCP segments parsed as incomplete or truncated; read until close, within the size bound, and reject a body shorter than its Content-Length. Refuse to send the client secret or a token without TLS to any host but localhost.
…lures Invalidating while a refresh was in flight let that refresh repopulate the cache with a token issued before the invalidation. Each refresh now carries the generation it started in, and later callers no longer join a refresh that was detached by invalidation. When every caller waiting on a shared refresh was cancelled, a failing refresh surfaced as a never-retrieved exception. Callers now wait without a shield wrapper and every refresh outcome is retrieved when it settles.
Pin the published 19.31.3 contracts wheel and call the renamed services: EventTypes.RegisterEventTypes (now checked for a failed command result) and Sequences.EventSequences.Append, whose response is wrapped in a command result. Event type contracts stay dynamically imported because their stub still declares an enum member named None. Document the 19.31.3 kernel and that 16.x kernels are no longer supported.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #33 (connection strings): this branch is based on
feature/connection-string-parser. Retarget tomainafter #33 merges.Added
/connect/token, typed errors (TokenAuthorizationError,TokenRequestError,TokenResponseError), conservative 30 second caching whenexpires_inis absent, proactive refresh, one shared refresh for concurrent callers, and cancellation that does not break other callers. (Implement async OAuth token handling #3)ChronicleClient: ensures an event store and theDefaultnamespace, registers an event type with a non-empty JSON schema and appends toevent-log, returning the sequence number. Channel and token resources close deterministically. (Complete the first authenticated append milestone #4)Samples/append_event), a real getting-started page, an authentication and TLS page, and opt-in integration tests against a development kernel.Changed
skipTlsValidation(defaulttrue) now has behavior: it trusts the local kernel's self-signed certificate only forlocalhostand loopback addresses. Every other host is verified against trusted roots, andca_certificatessupplies a private CA. Host names are always checked.grpciois a direct dependency.Known limits
cratis-chronicle-contracts19.31.3 wheel (GitHub release asset, SHA-256 pinned; PyPI publication is not planned). The client calls the 19.x contract names, so 16.x kernels are not supported: event type registration fails withUNIMPLEMENTEDthere. Verified againstcratis/chronicle:19.31.3-development.UNAUTHENTICATED.Fixed
(#3, #4)