fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(gateway): harden inbound auth schema and rename credential flags - #598

Merged
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening
Mar 23, 2026
Merged

fix(gateway): harden inbound auth schema and rename credential flags#598
tejaskash merged 2 commits into
aws:mainfrom
aidandaly24:fix/inbound-auth-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Hardens the Custom JWT authorizer schema and renames credential CLI flags for clarity. This is the foundational PR for the Custom JWT gateway feature — it tightens validation and fixes naming before the custom claims feature is added on top.

Schema hardening

  • HTTPS enforcement: OidcDiscoveryUrlSchema now rejects http:// URLs via .refine()
  • Strict mode: CustomJwtAuthorizerConfigSchema uses .strict() to reject unknown fields
  • Flexible constraints: allowedAudience and allowedClients are now individually optional, with a .superRefine() requiring at least one of allowedAudience, allowedClients, or allowedScopes
  • deployed-state.ts: Aligned with schema — allowedAudience/allowedClients optional, added allowedScopes

Flag rename (--agent-client-*--client-*)

These are gateway-level OAuth credentials, not agent credentials. The agent prefix was misleading:

  • --agent-client-id--client-id
  • --agent-client-secret--client-secret
  • Updated across: CLI types, validation, GatewayPrimitive, TUI wizard state/handlers/props, useCreateMcp hook

TUI improvements

  • HTTPS validation on discovery URL input in the JWT wizard
  • Simplified validateCommaSeparated helper (removed unused fieldName param)
  • Renamed internal prop names (onAgentClientIdonClientId, etc.)
  • Updated prompt labels to remove "Agent" prefix

Test updates

  • Schema tests: HTTPS rejection, .strict() rejection, scope-only acceptance, all-empty rejection
  • Validation tests: HTTPS check, at-least-one constraint, renamed credential fields
  • Integration tests: Updated --agent-client-id/--agent-client-secret--client-id/--client-secret

Related Issue

Extracted from #596

Documentation PR

N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 23, 2026 03:08
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@tejaskash

Copy link
Copy Markdown
Contributor

Code review

Found 1 issue:

  1. TUI wizard still forces allowedClients to be non-empty, but the schema and CLI validation now allow it to be optional (only requiring at least one of audience/clients/scopes). The clients sub-step (subStep 2) applies customValidation={validateCommaSeparated} which rejects empty input and lacks the allowEmpty prop, unlike the audience and scopes steps which both have allowEmpty. A user who provides only audience + scopes will be blocked at the clients step.

prompt="Allowed Clients (comma-separated, e.g., 7abc123def456)"
initialValue=""
onSubmit={onClients}
onCancel={onCancel}
customValidation={validateCommaSeparated}
/>
)}

🤖 Generated with Claude Code

- If this code review was useful, please react with 👍. Otherwise, react with 👎.

- Enforce HTTPS on OIDC discovery URL in schema and CLI validation
- Make allowedAudience/allowedClients optional with at-least-one
superRefine constraint (audience, clients, or scopes)
- Add .strict() to CustomJwtAuthorizerConfigSchema
- Rename --agent-client-id/--agent-client-secret to
--client-id/--client-secret across CLI, TUI, and primitives
- Add HTTPS validation to TUI discovery URL input
- Update deployed-state schema to match (optional audience/clients,
add allowedScopes)
- Update unit tests for new validation rules and field names
Constraint: OIDC spec requires HTTPS for discovery endpoints
Rejected: Keep --agent-client-id naming | confusing since these are
gateway-level OAuth credentials, not agent credentials
Confidence: high
Scope-risk: moderate
@aidandaly24
aidandaly24force-pushed the fix/inbound-auth-hardening branch from 460ccf6 to 2104fa0CompareMarch 23, 2026 19:25
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
The schema allows allowedClients to be empty when audience or scopes
are provided, but the TUI wizard sub-step still rejected empty input
via customValidation. Add allowEmpty and placeholder to match the
audience and scopes sub-steps, and remove the now-unused
validateCommaSeparated helper.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/m PR size: M labels Mar 23, 2026
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review comments addressed: clients step now allows empty input with allowEmpty prop.

@tejaskash
tejaskash merged commit bf1406c into aws:mainMar 23, 2026
16 of 18 checks passed
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 23, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
aidandaly24 added a commit to aidandaly24/agentcore-cli that referenced this pull request Mar 24, 2026
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (aws#598)
Confidence: high
Scope-risk: moderate
tejaskash pushed a commit that referenced this pull request Mar 24, 2026
…th (#599)
* feat(gateway): add custom claims validation and TUI wizard for JWT auth
Add custom JWT claims validation support and a full TUI wizard flow
for configuring Custom JWT gateway authorization.
Schema:
- Add ClaimMatchOperator, ClaimMatchValue, InboundTokenClaimValueType,
and CustomClaimValidation schemas with strict validation
- Add customClaims to CustomJwtAuthorizerConfigSchema and deployed-state
- Add --custom-claims CLI flag with JSON parsing and validation
TUI Wizard:
- Expand JWT config flow with custom claims manager (add/edit/done)
- Add claim name, operator, value, and value type sub-steps
- Show human-readable claim summary in confirm review
- Make client credentials optional (skip with empty Enter)
Testing:
- Add AddGatewayJwtConfig.test.tsx — full TUI component tests
- Add finishJwtConfig.test.ts — unit tests for config assembly
- Extend useAddGatewayWizard.test.tsx with JWT + custom claims flows
- Add GatewayPrimitive.test.ts for custom claims round-trip
- Extend validate.test.ts with custom claims validation cases
- Add TUI integration test (add-gateway-jwt.test.ts)
Constraint: Stacked on fix/inbound-auth-hardening (#598)
Confidence: high
Scope-risk: moderate
* fix(gateway): improve custom claim form navigation UX
Enter now advances to the next field instead of immediately submitting,
and up/down arrow keys navigate between fields for a more intuitive form
experience.
* fix(gateway): position cursor before placeholder in custom claim form
When a text field is empty, the cursor now appears before the placeholder
hint instead of after it, matching expected input behavior.
* test(gateway): update claim form test for Enter-advances-fields behavior
The test expected Enter to immediately submit and show a validation error,
but Enter now advances to the next field. Updated the test to press Enter
through all fields before expecting the submission validation error.
* fix: restore CLIENT_ID env var and move inline import to top-level
Restore writing both CLIENT_ID and CLIENT_SECRET to .env in
createManagedOAuthCredential, matching main branch behavior.
Move dynamic import of policyEnginePrimitive to a static top-level
import per AGENTS.md conventions.
* style: run prettier and fix test prop
Run prettier on 3 files and add missing existingPolicyEngines
prop to AddGatewayJwtConfig test defaults.
* ci: retrigger checks
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@aidandaly24@tejaskash