Class A2aCallbacks
java.lang.Object
com.xebialabs.xlrelease.a2a.callback.A2aCallbacks
Mints and validates the push-notification callbacks the gateway offers remote agents.
The token is HMAC-SHA256(bootSecret, taskId): stateless (nothing stored per task,
nothing to clean up), unforgeable without the secret, and scoped to exactly one task. The secret
is generated fresh at boot — deliberately not persisted: a callback that arrives after a restart
fails validation and is simply dropped, and the waiting task's slow polling heartbeat picks the
result up instead. Losing a wake-up costs latency, never correctness, which is the whole design:
callbacks accelerate, polling guarantees.
-
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptioncom.xebialabs.xlrelease.a2a.api.views.A2aCallbackcallbackFor(String taskId) The callback to offer a remote agent for wakingtaskId.booleanConstant-time validation of a presented token against the expected one fortaskId.
-
Constructor Details
-
A2aCallbacks
- Parameters:
serverUrl- supplier of the public server base URL (read per call so configuration changes are reflected immediately)servletPath- the DispatcherServlet base path the A2A endpoints hang off
-
-
Method Details
-
callbackFor
The callback to offer a remote agent for wakingtaskId. -
isValid
Constant-time validation of a presented token against the expected one fortaskId.
-