BREAKING CHANGE
- Removed
impl FromRequestParts for OrgId. The bare axum extractor allowed tenant-confusion — a client holding a valid token for org A could send X-Org-Id: <org B> and land at a handler that wrote to org B with org A's principal. Handlers must take OrganizationContext exclusively, which reconciles token claims, the X-Org-Id header, and any path parameter.
Added
OrgId::try_from_headers(&http::HeaderMap) -> Result<OrgId, OrgIdHeaderError> (feature http) — non-extractor parser for callers without an AuthLayer (webhook verifiers, out-of-band tooling).
OrgIdHeaderError with Missing, NotUtf8, Invalid variants.
examples/header_parser.rs demonstrating the sanctioned non-axum usage.
Migration
// Before (rejected — tenant-confusion loophole):
async fn handler(org_id: OrgId) { /* writes to org_id without reconciling auth */ }
// After:
async fn handler(ctx: OrganizationContext) {
let org_id = ctx.org_id;
// ctx also carries the authenticated Principal, RequestId, roles, and attestation.
}