Skip to content

fix(review): enforce KV bearer revocation on the next request - #1329

Merged
seonghobae merged 1 commit into
feat/review-gateway-preseeded-kvfrom
feat/review-gateway-kv-revocation-20260928
Sep 28, 2026
Merged

seonghobae merged 1 commit into
feat/review-gateway-preseeded-kvfrom
feat/review-gateway-kv-revocation-20260928

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Problem

The production review gateway reads split KV bearer credentials once at startup. Deleting or rotating the inference credential leaves the old token accepted until restart. This violates the next-request revocation condition in #1023.

Change

Use the existing SecurityConfig.bearer_verifier and principal_resolver seams to compare each presented token against the current split KV credentials. Missing, equal, or unavailable credentials deny access. The deployment principal remains stable across token rotation. This change does not claim workload-specific identity or admin browser-session revocation; those require separate contracts.

Verification

  • RED: the added HTTP regression returned 200 for /v1/models after deleting the inference KV credential.
  • GREEN: 76 focused review-gateway, security-hardening, and CLI-auth tests pass; the regression covers inference delete/rotate, admin delete, and no provider send after revocation.
  • git diff --check passed.

Standard

RFC 7009 describes invalidating revoked credentials; RFC 7662 explains that a resource server relying on revocable tokens must obtain current validity. This PR applies that principle to this gateway's local KV bearer mode; it does not implement an OAuth revocation or introspection endpoint.

Stacked on #1321. Refs #1023.

Read the current split credentials during authorization so deleted or rotated review tokens stop working on the next request. Keep a stable deployment principal across rotation.

Refs #1023
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: e488dfc4-68b5-4ef9-b61f-db00c6a3a6e8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae merged commit fcc5a68 into feat/review-gateway-preseeded-kv Sep 28, 2026
2 of 6 checks passed
@seonghobae
seonghobae deleted the feat/review-gateway-kv-revocation-20260928 branch September 28, 2026 06:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant