feat: Enable authentication in all services#37
Merged
Conversation
Integrates authentication middleware into API Gateway, Sessions, and Memory services with configurable enforcement. What's Changed: - Add authentication middleware to API Gateway with user identity forwarding - Add authentication middleware to Sessions service - Add authentication middleware to Memory service - Update .env.example with comprehensive auth configuration - Set AUTH_REQUIRE_AUTH=false by default for development Features: - Automatic JWT and API key authentication on all routes - Configurable exempt paths (health, docs, metrics) - User identity forwarded from Gateway to downstream services via headers - Authentication can be enabled/disabled per environment - All services log authentication status on startup 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
What's Included
API Gateway Authentication
AuthenticationMiddlewareX-User-IDandX-Org-IDheaders when user is authenticatedSessions Service Authentication
AuthenticationMiddlewareMemory Service Authentication
AuthenticationMiddlewareEnvironment Configuration
How It Works
Development Mode (Default)
# Authentication disabled by default AUTH_REQUIRE_AUTH=falseProduction Mode
User Identity Forwarding
Gateway extracts user identity from authentication and forwards to services:
Configuration
Quick Start
Exempt Paths
These paths don't require authentication:
/health,/health/live,/health/ready,/health/detailed,/health/services/docs,/redoc,/openapi.json/metricsTest Plan
Next Steps
Once merged, developers can:
🤖 Generated with Claude Code