Files
OmniRoute/tests/unit
diegosouzapw 858cdfd9b7 fix(a2a): accept dashboard session auth on /a2a route (#12888)
The A2A dashboard's Run message/send and Run message/stream buttons
fetch("/a2a", ...) with no Authorization header. authenticateA2ARequest()
only checked for a Bearer/x-api-key, unlike clientApiPolicy (/api/v1/*)
which falls back to isDashboardSessionAuthenticated() when no key is
present. Add that same fallback to the A2A auth helper, give a
session-authenticated caller with no API key a stable 'dashboard' owner
id in resolveA2AOwner(), and send credentials: same-origin from the
dashboard playground fetches so the session cookie always rides along.
2026-09-10 15:35:21 -03:00
..
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00
2026-08-26 14:25:01 -03:00