Skip to content

Expose caller authorization for extension requests - #415

Merged
maximelb merged 1 commit into
masterfrom
fbA/extension-caller-auth
Oct 1, 2026
Merged

maximelb merged 1 commit into
masterfrom
fbA/extension-caller-auth

Conversation

@maximelb

@maximelb maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Some extension actions require the authenticated caller's permissions, but the generic CLI request command could not select the SDK's existing caller authorization path. Add explicit extension request --impersonate forwarding; requests continue to omit caller identity unless selected. Help and the CLI reference explain the flag.

Validation: all 4,664 unit and microbenchmark correctness tests pass (5 existing skips). Actual Click invocation tests cover both default and selected behavior through the real SDK request builder; disabling forwarding fails the selected authorization assertion while the default control still passes. An authenticated action requiring caller identity refused the default request and accepted the flagged request.

Risk: selecting the flag intentionally sends the current caller identity through the existing authenticated SDK path; it grants no additional permissions. No token is printed or persisted by this change. Live check: invoke a caller-authorized action with and without the flag and verify only the flagged request supplies the existing identity; unexpected permissions or identity forwarding by default falsify the change.

🤖 Generated with Claude Code

@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

@maximelb
maximelb merged commit 1544593 into master Oct 1, 2026
6 checks passed
@maximelb
maximelb deleted the fbA/extension-caller-auth branch October 1, 2026 23:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants