Skip to content

[fix] require an account to subscribe to the alert and manager streams - #4272

Open
Duansg wants to merge 2 commits into
apache:masterfrom
Duansg:fix-sse-authz
Open

[fix] require an account to subscribe to the alert and manager streams#4272
Duansg wants to merge 2 commits into
apache:masterfrom
Duansg:fix-sse-authz

Conversation

@Duansg

@Duansg Duansg commented Jul 29, 2026

Copy link
Copy Markdown
Member

What's changed?

Require authentication for the alert/manager SSE streams; the front end switches to fetch so it can carry credentials, plus a connection timeout and a concurrency cap.

Checklist

  • I have read the Contributing Guide
  • I have written the necessary doc or comment.
  • I have added the necessary unit tests and all cases have passed.

Add or update API

  • I have added the necessary e2e tests and all cases have passed.

@zqr10159 zqr10159 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed against the 1.9.0 pre-release alert and manager SSE findings. The streams are removed from the authentication exclusions, the browser sends bearer authorization, and emitter lifetime/capacity are bounded. The focused local contracts pass (10 tests) and CI is green.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants