Skip to main content

Module edge_auth

Module edge_auth 

Source
Expand description

Core-side gate for the edge/core split. When the server runs with --role core, every request must carry the shared secret the edge adds (X-M4A-Edge-Secret). The tunnel and a firewall allowlist are the first line; this header is the second, so a stray process on the tunnel network cannot talk to the core. The secret comes from the environment and is never logged.

Constants§

EDGE_SECRET_HEADER
Header name carrying the shared secret edge -> core.

Functions§

require_edge_secret
Wraps router so requests without the right secret get a Matrix-shaped 401.
require_link_token
Barrier token gate for a standalone core reached directly by a product server (M4A_LINK_TOKEN): every request outside the public protocol surfaces must carry x-m4a-link-token. The header is removed before routing.