Class A2aPushNotificationSender

java.lang.Object
com.xebialabs.xlrelease.a2a.callback.A2aPushNotificationSender

public class A2aPushNotificationSender extends Object
The inbound counterpart of the callback servlet: when a release backing an A2A task changes state, POST the mapped task to the webhook its remote caller registered — so external agents stop polling GetTask the same way our tasks stopped polling them.

Event-driven off the release event bus, with three deliberate guards:

  • registry first: every task event in the system passes through here, so the cheap map lookup decides before anything else runs;
  • state-change dedupe: a notification goes out only when the mapped A2A state actually changed — a release full of quick script tasks does not spam its watcher;
  • allowlist-gated POSTs: a webhook URL is caller-supplied, which is the textbook SSRF vector — targets must be covered by the same agent allowlist as outbound calls (A2aAllowlistPolicy), or the registration is refused at delivery time and dropped.

Delivery is best-effort and fire-and-forget on the auxiliary executor: a failed POST is logged and the caller falls back to polling, which stays correct by design. Terminal states unregister the webhook after the final notification.

  • Constructor Details

  • Method Details

    • onTaskExecution

      public void onTaskExecution(com.xebialabs.xlrelease.domain.events.TaskExecutionEvent event)
    • onReleaseCompleted

      public void onReleaseCompleted(com.xebialabs.xlrelease.domain.events.ReleaseCompletedEvent event)
    • onReleaseFailed

      public void onReleaseFailed(com.xebialabs.xlrelease.domain.events.ReleaseFailedEvent event)
    • onReleaseAborted

      public void onReleaseAborted(com.xebialabs.xlrelease.domain.events.ReleaseAbortedEvent event)