Skip to content

Refactor Passthrough Token handling into reusable middleware - #135

Closed
cubap wants to merge 2 commits into
mainfrom
cubap-improved-invention
Closed

cubap wants to merge 2 commits into
mainfrom
cubap-improved-invention

Conversation

@cubap

@cubap cubap commented Sep 30, 2026

Copy link
Copy Markdown
Member

Why

The existing Passthrough Token implementation duplicated logic across routes and used a placeholder Authorization header, causing maintenance overhead and potential errors. A modular approach improves consistency and makes future extensions easier.

What was done

  • Added passthrough.js providing resolveAuthorization and requirePassthroughAllowed middleware.
  • Updated tokens.js to bypass token refresh when a client-supplied Authorization header is present.
  • Refactored create and update routes to import the new helpers, enforce the kill‑switch before token checks, and forward the exact client Authorization header.
  • Updated README with a Passthrough Token Mode section and a Mermaid diagram showing the middleware flow.
  • Added test/routes/passthrough.test.js to verify header forwarding.
  • Prepared groundwork for delete and overwrite routes (imports added, pending final header replacement).

Notes

  • The new middleware centralizes Authorization handling and respects the ALLOW_PASSTHROUGH_TOKENS environment variable, returning 403 when disabled.
  • Documentation now explains the feature and includes a visual diagram for developers.
  • All changes are covered by the new unit test.

Checklist

  • Code compiles
  • Tests pass
  • Documentation updated
  • Finalize delete and overwrite routes (planned for subsequent PR)

cubap and others added 2 commits September 29, 2026 15:18
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
- Added reusable middleware (passthrough.js) for Authorization resolution and kill‑switch enforcement.
- Updated token handling to bypass refresh when client token is present.
- Modified create and update routes to use new middleware and forward Authorization header.
- Updated README with Passthrough Token Mode documentation and Mermaid diagram.
- Added test to verify Authorization header forwarding.
- Prepared for full route coverage (delete, overwrite pending).
@cubap
cubap requested a review from thehabes as a code owner September 30, 2026 14:36
@thehabes

Copy link
Copy Markdown
Member

argh

@thehabes thehabes closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants