Skip to content

xds: Add ext_authz response handling - #13037

Merged
sauravzg merged 3 commits into
masterfrom
dev/sauravzg/response-handling
Sep 9, 2026
Merged

sauravzg merged 3 commits into
masterfrom
dev/sauravzg/response-handling

Conversation

@sauravzg

@sauravzg sauravzg commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Part 2 of the client-side ext_authz filter. Sits on top of #12493 (merged).

Supersedes #12896, which was auto-closed when its base branch was deleted and cannot be reopened due to branch rebase. Previously reviewed and approved by @kannanjgithub in #12896.

Adds CheckResponseHandler, which interprets the CheckResponse from the authorization service. It evaluates OkHttpResponse vs DeniedHttpResponse, maps HTTP status codes to gRPC statuses, applies failure_mode_allow semantics when the authz server is unreachable, and validates decoder header mutations against the configured HeaderMutationRulesConfig.

AuthzResponse is the resulting value object carrying the allow/deny decision, the gRPC status for denied calls, and any header/trailer mutations to apply.

Part 2 of the client-side ext_authz filter. Sits on top of #12493.

Adds CheckResponseHandler, which interprets the CheckResponse from
the authorization service. It evaluates OkHttpResponse vs
DeniedHttpResponse, maps HTTP status codes to gRPC statuses, applies
failure_mode_allow semantics when the authz server is unreachable, and
validates decoder header mutations against the configured
HeaderMutationRulesConfig.

AuthzResponse is the resulting value object carrying the allow/deny
decision, the gRPC status for denied calls, and any header/trailer
mutations to apply.
@sauravzg
sauravzg force-pushed the dev/sauravzg/response-handling branch from 18570ea to 73686fd Compare September 9, 2026 14:29
@sauravzg
sauravzg merged commit cf5c0b2 into master Sep 9, 2026
24 of 25 checks passed
@sauravzg
sauravzg deleted the dev/sauravzg/response-handling branch September 9, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants