Class A2aCallbacks

java.lang.Object
com.xebialabs.xlrelease.a2a.callback.A2aCallbacks

public class A2aCallbacks extends Object
Mints and validates the push-notification callbacks the gateway offers remote agents.

The token is HMAC-SHA256(bootSecret, taskId): stateless (nothing stored per task, nothing to clean up), unforgeable without the secret, and scoped to exactly one task. The secret is generated fresh at boot — deliberately not persisted: a callback that arrives after a restart fails validation and is simply dropped, and the waiting task's slow polling heartbeat picks the result up instead. Losing a wake-up costs latency, never correctness, which is the whole design: callbacks accelerate, polling guarantees.

  • Constructor Details

    • A2aCallbacks

      public A2aCallbacks(Supplier<String> serverUrl, String servletPath)
      Parameters:
      serverUrl - supplier of the public server base URL (read per call so configuration changes are reflected immediately)
      servletPath - the DispatcherServlet base path the A2A endpoints hang off
  • Method Details

    • callbackFor

      public com.xebialabs.xlrelease.a2a.api.views.A2aCallback callbackFor(String taskId)
      The callback to offer a remote agent for waking taskId.
    • isValid

      public boolean isValid(String taskId, String presentedToken)
      Constant-time validation of a presented token against the expected one for taskId.