Skip to content

Clear the authentication and middleware quality gate #33

Description

@jonbaldie

Parent

#27 — Bring production TypeScript to messcript's idiomatic ruleset

What to build

Authentication and middleware refactoring passes the structural-quality gate while bearer-token enforcement, health-check exemptions, forwarded-client handling, middleware ordering, and rate-limit responses remain unchanged.

Acceptance criteria

  • The middleware production unit reports zero selected messcript findings under the pinned policy.
  • Real HTTP requests verify health access without credentials, authentication failures, authenticated access, rate limiting before authentication, and forwarded-client behavior.
  • The refactor contains no source suppression or policy weakening.

Blocked by

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentFully specified and ready for an implementation agent

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions