Request
Please provide a supported extension seam that can authorize every incoming
HTTP and MCP transport request before native route handling. The hook should
receive method, normalized path, relevant transport headers and the existing
request context, and should be able to return an HTTP denial without replacing
or mutating native handlers.
Motivation
Hindsight's tenant and operation extensions cover bank operations well, but
some native surfaces answer before tenant authentication: utility routes,
generated documentation/OpenAPI, deprecated responses and MCP's no-session GET
probe. HttpExtension adds routers; it cannot attach a documented dependency or
middleware to existing routes. Undocumented FastAPI mutation would be brittle
for downstream operators.
Health and metrics exceptions vary by deployment, so a fixed upstream policy is
less useful than a supported fail-closed hook. Existing bank operation
validators should remain authoritative; this request covers transport admission
and route-level exclusions, not a replacement authorization model.
Proposed shape
A single pre-routing callback with an explicit allow/reject result is enough.
It should run for generated routes and MCP transport probes as well as ordinary
REST handlers, preserve normal extension configuration/lifecycle, and have
tests proving fail-closed behavior when the extension rejects or errors.
Related issue #2343 discusses broader auth profile and extension needs. This
request is limited to a supported pre-routing admission seam for existing
native HTTP and MCP handlers.
Request
Please provide a supported extension seam that can authorize every incoming
HTTP and MCP transport request before native route handling. The hook should
receive method, normalized path, relevant transport headers and the existing
request context, and should be able to return an HTTP denial without replacing
or mutating native handlers.
Motivation
Hindsight's tenant and operation extensions cover bank operations well, but
some native surfaces answer before tenant authentication: utility routes,
generated documentation/OpenAPI, deprecated responses and MCP's no-session GET
probe.
HttpExtensionadds routers; it cannot attach a documented dependency ormiddleware to existing routes. Undocumented FastAPI mutation would be brittle
for downstream operators.
Health and metrics exceptions vary by deployment, so a fixed upstream policy is
less useful than a supported fail-closed hook. Existing bank operation
validators should remain authoritative; this request covers transport admission
and route-level exclusions, not a replacement authorization model.
Proposed shape
A single pre-routing callback with an explicit allow/reject result is enough.
It should run for generated routes and MCP transport probes as well as ordinary
REST handlers, preserve normal extension configuration/lifecycle, and have
tests proving fail-closed behavior when the extension rejects or errors.
Related issue #2343 discusses broader auth profile and extension needs. This
request is limited to a supported pre-routing admission seam for existing
native HTTP and MCP handlers.