Repository navigation
feat(cas): let browsers cache downloads - #3553
Conversation
The CAS download endpoint now accepts the token in an Authorization Bearer header, in addition to the t query parameter, so the download URL stays the same for a digest. When both are present the header wins. Downloads send ETag with the quoted digest and Cache-Control private, no-cache. A request whose If-None-Match matches the digest gets a 304 Not Modified after the token and the object metadata are checked, without copying the object from the storage backend and without an audit event. Refs chainloop-dev#3549 Assisted-by: Claude Code Signed-off-by: Jose I. Paris <jiparis@chainloop.dev> Chainloop-Trace-Sessions: 920bece2-38f4-43dd-9acc-d07e0325b568
PR validation — ✅ 3 passing
AI Session Checks — 🔴 40% · ✅ 0 failing
|
| Status | Attribution | File | Lines |
|---|---|---|---|
| modified | ai | app/artifact-cas/internal/service/download_test.go |
+149 / -9 |
| modified | ai | pkg/middlewares/http/jwt.go |
+28 / -6 |
| modified | ai | app/artifact-cas/internal/service/download.go |
+32 / -0 |
| modified | ai | pkg/middlewares/http/jwt_test.go |
+18 / -7 |
| modified | ai | app/artifact-cas/internal/server/http.go |
+1 / -1 |
Policies (4)
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | ai-config-ai-agents-allowed |
ai-coding-session-920bec |
- |
| ✅ Passed | ai-config-no-dangerous-commands |
ai-coding-session-920bec |
- |
| ✅ Passed | ai-config-no-secrets |
ai-coding-session-920bec |
- |
| ✅ Passed | ai-config-mcp-servers-allowed |
ai-coding-session-920bec |
- |
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
Scans not applied (3)
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
Security context
✅ Nothing this change touches has a recorded security-fix history.
View in Chainloop ↗ · How this works ↗
Powered by Chainloop and Chainloop Trace
|
@migmartri the corresponding spec is here too #3552 |
Summary
Lets browsers cache CAS downloads, as the spec in #3552 describes (R-001 to R-005).
Authorization: Bearerheader, in addition to thetquery parameter. The download URL then stays the same for a digest, so the browser cache can find its copy. When both are present, the header wins and a bad header does not fall back to the query. The CLI and the existing download links keep working with the query token.ETagwith the quoted digest andCache-Control: private, no-cache.If-None-Matchgets304 Not Modifiedwith the same headers. The CAS first checks the token and the object metadata. It does not copy the object from the storage backend, and it does not record a download audit event.Refs #3549
This change was written with AI assistance (Claude Code).
🤖 Generated with Claude Code