Skip to content

Feature request: supported pre-routing authorization hook for HTTP and MCP #4242

Description

@bagutzu

Request

Please provide a supported extension seam that can authorize every incoming
HTTP and MCP transport request before native route handling. The hook should
receive method, normalized path, relevant transport headers and the existing
request context, and should be able to return an HTTP denial without replacing
or mutating native handlers.

Motivation

Hindsight's tenant and operation extensions cover bank operations well, but
some native surfaces answer before tenant authentication: utility routes,
generated documentation/OpenAPI, deprecated responses and MCP's no-session GET
probe. HttpExtension adds routers; it cannot attach a documented dependency or
middleware to existing routes. Undocumented FastAPI mutation would be brittle
for downstream operators.

Health and metrics exceptions vary by deployment, so a fixed upstream policy is
less useful than a supported fail-closed hook. Existing bank operation
validators should remain authoritative; this request covers transport admission
and route-level exclusions, not a replacement authorization model.

Proposed shape

A single pre-routing callback with an explicit allow/reject result is enough.
It should run for generated routes and MCP transport probes as well as ordinary
REST handlers, preserve normal extension configuration/lifecycle, and have
tests proving fail-closed behavior when the extension rejects or errors.

Related issue #2343 discusses broader auth profile and extension needs. This
request is limited to a supported pre-routing admission seam for existing
native HTTP and MCP handlers.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions