Class A2aCallbackServlet
java.lang.Object
jakarta.servlet.GenericServlet
jakarta.servlet.http.HttpServlet
com.xebialabs.xlrelease.a2a.callback.A2aCallbackServlet
- All Implemented Interfaces:
jakarta.servlet.Servlet,jakarta.servlet.ServletConfig,Serializable
public class A2aCallbackServlet
extends jakarta.servlet.http.HttpServlet
Receives a remote agent's push notification and wakes the waiting Release task — nothing more.
Security model, deliberately spelled out because this endpoint is exempt from platform authentication (a third-party agent has no Release credentials):
- the request must carry the task-scoped HMAC token minted by
A2aCallbacks— in the callback URL's own query string, or the spec'sX-A2A-Notification-Tokenheader; - the notification body is never read, parsed, or trusted — a valid callback only resumes the suspended task, which then re-reads the remote task's state itself over the governed, credentialed channel;
- therefore the worst a replayed or forged-with-stolen-token request can do is trigger one idempotent extra poll of a task that was already polling on a timer anyway.
Responses are deliberately uninformative: 204 on acceptance, 401 otherwise — never revealing whether a task id exists. Resume failures (task already finished, unknown id) are logged and still answered 204: the notification was valid, and the sender can do nothing with the detail.
- See Also:
-
Field Summary
Fields inherited from class jakarta.servlet.http.HttpServlet
LEGACY_DO_HEAD -
Constructor Summary
ConstructorsConstructorDescriptionA2aCallbackServlet(A2aCallbacks callbacks, com.xebialabs.xlrelease.service.ExecutionService executionService) -
Method Summary
Modifier and TypeMethodDescriptionprotected voiddoPost(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) Methods inherited from class jakarta.servlet.http.HttpServlet
doDelete, doGet, doHead, doOptions, doPatch, doPut, doTrace, getLastModified, init, isSensitiveHeader, service, serviceMethods inherited from class jakarta.servlet.GenericServlet
destroy, getInitParameter, getInitParameterNames, getServletConfig, getServletContext, getServletInfo, getServletName, init, log, log
-
Constructor Details
-
A2aCallbackServlet
public A2aCallbackServlet(A2aCallbacks callbacks, com.xebialabs.xlrelease.service.ExecutionService executionService)
-
-
Method Details
-
doPost
protected void doPost(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) throws IOException - Overrides:
doPostin classjakarta.servlet.http.HttpServlet- Throws:
IOException
-