Skip to content

feat(auth): add service-to-service authentication - #165

Merged
heymariam merged 2 commits into
Dorisio:mainfrom
modrispath:feat/140-drips
Oct 1, 2026
Merged

heymariam merged 2 commits into
Dorisio:mainfrom
modrispath:feat/140-drips

Conversation

@modrispath

Copy link
Copy Markdown
Contributor

Summary

Adds secure configuration-backed authentication for internal service-to-service requests without changing end-user JWT authentication.

Related Issue

Closes #140

What Changed

  • Adds internal service authentication using API keys.
  • Uses SHA-256 key digests and constant-time comparison.
  • Adds service identity, key identity, roles, and scopes to the request context.
  • Supports key expiration and not-before validation.
  • Supports current and previous keys during controlled key rotation.
  • Fails closed when service authentication is missing or incorrectly configured.
  • Adds typed request.service context.
  • Adds service scope and role guards.
  • Adds internal request classification and service-aware rate-limit bucketing.
  • Adds optional mTLS socket verification.
  • Does not trust arbitrary client-certificate headers.
  • Adds non-secret audit logging for accepted and rejected service requests.
  • Ensures API keys and other credential material are never written to logs.
  • Adds configuration and environment documentation.
  • Adds service-authentication rotation and proxy/mTLS operational guidance.
  • Adds focused tests for:
    • valid service keys;
    • invalid keys;
    • expired keys;
    • previous-key rotation overlap;
    • malformed authorization headers;
    • missing service credentials;
    • scope and role denial;
    • mTLS verification;
    • service-aware rate limiting.

Validation

  • Service-authentication and rate-limit tests pass.
  • 28 focused tests pass.
  • ESLint passes for the modified service-authentication files.

The full repository type-check remains affected by pre-existing Prisma generation and unrelated baseline errors.

This PR is submitted as a draft for maintainer review. It must not be merged by the contributor.

@drips-wave

drips-wave Bot commented Sep 29, 2026

Copy link
Copy Markdown

@modrispath Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@heymariam

Copy link
Copy Markdown
Contributor

@modrispath well done and thanks for contributing, resolve the conflicts so we can check and merge

@heymariam
heymariam merged commit f9afdde into Dorisio:main Oct 1, 2026
1 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Service-to-Service Authentication (Internal API Security)

2 participants