HTTP session hooks · NVIDIA/OpenShell#4359 1 / 5
Reviewer walkthrough · supervisor middleware

HTTP session hooks: streaming request and response middleware

The PR replaces the v1 HTTP middleware hooks with two bidirectional streaming RPCs. Middleware can now inspect bodies of any size, and decide about connections OpenShell cannot parse as HTTP.

  • Streaming APIEvaluateHttpRequestSession and EvaluateHttpResponseSession, one stream per HTTP message and stage. A preflight picks continue, reject, or inspect (BUFFERED or STREAM).
  • Opt in by capabilitySame HTTP_REQUEST / HTTP_RESPONSE bindings. A service that requires openshell.supervisor-middleware.http-session gets the new RPCs. No new operations or versioned enums.
  • Always fail-closedon_error: fail_open is rejected for session hook services.
  • v1 deprecatedEvaluateHttpRequest and HttpResponsePreReturn keep working and are removed in 0.2.0.
github.com/NVIDIA/OpenShell/pull/4359

In this deck

  1. Before and after
  2. Shape of the new API
  3. How a service selects the hook version
  4. Migrating a v1 service
  5. Next iterations
  6. Preflight and body eligibility rules
  7. Chain ordering and when the head commits
  8. STREAM queues, stalls, and deadlines
  9. Failure semantics per phase
  10. Code map for the diff