Class A2aAgentCardServlet

java.lang.Object
jakarta.servlet.GenericServlet
jakarta.servlet.http.HttpServlet
com.xebialabs.xlrelease.a2a.server.A2aAgentCardServlet
All Implemented Interfaces:
jakarta.servlet.Servlet, jakarta.servlet.ServletConfig, Serializable

public class A2aAgentCardServlet extends jakarta.servlet.http.HttpServlet
Serves Release's A2A Agent Card at the spec's well-known path (/.well-known/agent-card.json): identity, the JSON-RPC service endpoint, and the currently visible skills. This is how external agents discover Release.

Answers 404 while the A2A feature is disabled (mirroring A2aServerEnabledFilter on the endpoint itself). Read-only mode hides mutating skills from the card — enforcement on the call path is the endpoint servlet's job; the card only ever advertises what would be accepted.

The card is rebuilt per request: the endpoint URL follows the configured server URL, and the skill list follows the read-only toggle, with no restart.

Why the SDK's AgentCard rather than a hand-built JSON tree. This card used to be assembled field by field, and it drifted: it advertised protocolVersion: "1.0" while emitting the 0.3 body — a top-level url and preferredTransport, both of which 1.0 replaced with supportedInterfaces. A spec-compliant 1.0 client reading that card finds no callable interface and refuses to register Release at all. Building the record and letting A2aServerJson write it makes that class of drift a compile error instead.

See Also:
  • Field Summary

    Fields inherited from class jakarta.servlet.http.HttpServlet

    LEGACY_DO_HEAD
  • Constructor Summary

    Constructors
    Constructor
    Description
    A2aAgentCardServlet(Supplier<String> endpointUrl, Supplier<String> serverVersion, A2aSkillRegistry skills, BooleanSupplier enabled, BooleanSupplier readOnly)
     
  • Method Summary

    Modifier and Type
    Method
    Description
    protected void
    doGet(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response)
     

    Methods inherited from class jakarta.servlet.http.HttpServlet

    doDelete, doHead, doOptions, doPatch, doPost, doPut, doTrace, getLastModified, init, isSensitiveHeader, service, service

    Methods inherited from class jakarta.servlet.GenericServlet

    destroy, getInitParameter, getInitParameterNames, getServletConfig, getServletContext, getServletInfo, getServletName, init, log, log

    Methods inherited from class java.lang.Object

    clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
  • Constructor Details

    • A2aAgentCardServlet

      public A2aAgentCardServlet(Supplier<String> endpointUrl, Supplier<String> serverVersion, A2aSkillRegistry skills, BooleanSupplier enabled, BooleanSupplier readOnly)
      Parameters:
      endpointUrl - supplier of the full public A2A endpoint URL (read per request so server-URL changes are reflected immediately)
      serverVersion - the product version advertised on the card
      skills - all built-in skills; read-only filtering happens per request
      enabled - whether the A2A feature is on, read per request
      readOnly - whether the A2A feature is in read-only mode, read per request
  • Method Details

    • doGet

      protected void doGet(jakarta.servlet.http.HttpServletRequest request, jakarta.servlet.http.HttpServletResponse response) throws IOException
      Overrides:
      doGet in class jakarta.servlet.http.HttpServlet
      Throws:
      IOException