Skip to content

feat: secure ledger internal endpoints - #26

Merged
ramioooz merged 1 commit into
mainfrom
feature/ledger-service-security
Sep 12, 2026
Merged

ramioooz merged 1 commit into
mainfrom
feature/ledger-service-security

Conversation

@ramioooz

Copy link
Copy Markdown
Member

Summary

  • Add stateless Spring Security resource-server support to Ledger Service.
  • Require ledger.internal scope for /internal/v1/ledger-entries/**.
  • Keep health/info and OpenAPI endpoints available for probes and internal documentation.
  • Validate issuer and base64 HMAC JWT configuration using the existing platform contract.
  • Add focused decoder configuration coverage without redundant unit tests.

Verification

  • ./mvnw -Dtest=JwtDecoderConfigurationTest test
  • ./mvnw -DskipTests package
  • Full unit suite during package: 36 tests passed.
  • git diff --check

Notes

  • This PR does not merge directly to main.
  • Runtime deployment must provide auth.jwt.secret through the existing secret-backed configuration and auth.jwt.issuer.

@ramioooz
ramioooz merged commit ccd1380 into main Sep 12, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant