Package com.xebialabs.xlrelease.a2a.gateway
package com.xebialabs.xlrelease.a2a.gateway
-
ClassesClassDescriptionThe governed implementation of
A2aAgentGateway: every call passes the A2A feature toggle and the agent-allowlist check — on the caller-supplied URL and on the service endpoint the Agent Card names — before any byte leaves the host, and every outcome is logged with the agent, method and remote task id (never with credentials or payloads).The one implementation of the A2A agent allowlist, shared by every component that sends a byte to a caller-influenced URL: the outbound gateway (agent calls) and the push-notification sender (webhook POSTs registered by external callers — the classic SSRF vector, closed by requiring webhook targets to sit on the same allowlist as the agents themselves).