feat(auth): include authentication in workspace and tht diagnostics

This commit is contained in:
2026-08-17 15:51:16 +02:00
parent cb0e873ed7
commit 3ed00ff086
19 changed files with 1050 additions and 34 deletions
+10 -3
View File
@@ -11,6 +11,7 @@ import {
} from "./schema.js";
import type { WorkspaceErrorCode } from "./types.js";
import type { SemanticRuntimeConfig } from "./runtime-renderer.js";
import type { AuthDiagnostics } from "../auth/diagnostics.js";
export interface Diagnostic {
level: "error" | "warning" | "info";
@@ -20,11 +21,17 @@ export interface Diagnostic {
message: string;
}
export interface WorkspaceDiagnostics {
/** Connector-only result produced before the route aggregates authentication. */
export interface ConnectorDiagnostics {
activatable: boolean;
diagnostics: Diagnostic[];
}
/** The HTTP workspace diagnostic contract always includes the shared authentication report. */
export interface WorkspaceDiagnostics extends ConnectorDiagnostics {
authentication: AuthDiagnostics;
}
interface DiagnosticResource {
database?: string;
schema?: string;
@@ -384,7 +391,7 @@ async function diagnoseValidatedWorkspace(
adapters: DiagnosticAdapters,
timeoutMs: number,
semanticRuntime: SemanticRuntimeConfig,
): Promise<WorkspaceDiagnostics> {
): Promise<ConnectorDiagnostics> {
const evidenceField = descriptor.evidence?.source.type === "http"
? "evidence.source.authentication"
: descriptor.evidence?.source.type === "s3"
@@ -533,7 +540,7 @@ export function createWorkspaceDiagnoser(
workspace: WorkspaceDescriptor,
bindings: RuntimeBindings,
_options: { writeProbe: boolean },
): Promise<WorkspaceDiagnostics> {
): Promise<ConnectorDiagnostics> {
requireSupportedDescriptor(workspace);
const descriptor = validateWorkspaceDescriptor(workspace);
return await diagnoseValidatedWorkspace(descriptor, bindings, adapters, timeoutMs, semanticRuntime);