Class A2aCallbackServlet

java.lang.Object
jakarta.servlet.GenericServlet
jakarta.servlet.http.HttpServlet
com.xebialabs.xlrelease.a2a.callback.A2aCallbackServlet
All Implemented Interfaces:
jakarta.servlet.Servlet, jakarta.servlet.ServletConfig, Serializable

public class A2aCallbackServlet extends jakarta.servlet.http.HttpServlet
Receives a remote agent's push notification and wakes the waiting Release task — nothing more.

Security model, deliberately spelled out because this endpoint is exempt from platform authentication (a third-party agent has no Release credentials):

  • the request must carry the task-scoped HMAC token minted by A2aCallbacks — in the callback URL's own query string, or the spec's X-A2A-Notification-Token header;
  • the notification body is never read, parsed, or trusted — a valid callback only resumes the suspended task, which then re-reads the remote task's state itself over the governed, credentialed channel;
  • therefore the worst a replayed or forged-with-stolen-token request can do is trigger one idempotent extra poll of a task that was already polling on a timer anyway.

Responses are deliberately uninformative: 204 on acceptance, 401 otherwise — never revealing whether a task id exists. Resume failures (task already finished, unknown id) are logged and still answered 204: the notification was valid, and the sender can do nothing with the detail.

See Also:
  • Field Summary

    Fields inherited from class jakarta.servlet.http.HttpServlet

    LEGACY_DO_HEAD
  • Constructor Summary

    Constructors
    Constructor
    Description
    A2aCallbackServlet(A2aCallbacks callbacks, com.xebialabs.xlrelease.service.ExecutionService executionService)
     
  • Method Summary

    Modifier and Type
    Method
    Description
    protected void
    doPost(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response)
     

    Methods inherited from class jakarta.servlet.http.HttpServlet

    doDelete, doGet, doHead, doOptions, doPatch, doPut, doTrace, getLastModified, init, isSensitiveHeader, service, service

    Methods inherited from class jakarta.servlet.GenericServlet

    destroy, getInitParameter, getInitParameterNames, getServletConfig, getServletContext, getServletInfo, getServletName, init, log, log

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • A2aCallbackServlet

      public A2aCallbackServlet(A2aCallbacks callbacks, com.xebialabs.xlrelease.service.ExecutionService executionService)
  • Method Details

    • doPost

      protected void doPost(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) throws IOException
      Overrides:
      doPost in class jakarta.servlet.http.HttpServlet
      Throws:
      IOException