Skip to content

feat(terminal-types): add auth policy pinning for session modes - #19

Merged
nkarpov merged 1 commit into
mainfrom
feat/terminal-type-auth-policy
Mar 2, 2026
Merged

nkarpov merged 1 commit into
mainfrom
feat/terminal-type-auth-policy

Conversation

@nkarpov

@nkarpov nkarpov commented Mar 2, 2026

Copy link
Copy Markdown
Owner

Summary

  • add authPolicy to terminal type manifests with supported values: both (default), user, m2m
  • enforce type auth policy on session creation and auth-mode changes in the API layer
  • return AUTH_MODE_NOT_ALLOWED_FOR_SESSION_TYPE when callers request disallowed modes
  • update tab auth badge UX: disable/lock toggle for pinned policies
  • document authPolicy in terminal type docs and main README

Behavior

  • both: existing behavior, mode can toggle between m2m and user
  • user: sessions are pinned to user auth, toggle disabled
  • m2m: sessions are pinned to m2m auth, toggle disabled

Validation

  • npm run check
  • npm test

Added/updated tests for:

  • default authPolicy exposure on session types
  • create behavior for pinned user and m2m policies
  • rejection of disallowed explicit auth mode on create
  • rejection of disallowed auth-mode switches after session creation

@nkarpov
nkarpov merged commit d031ea4 into main Mar 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant